PT-2022-17827 · Horner Automation · Rcc 972
M1Etz
·
Published
2022-12-02
·
Updated
2022-12-12
·
CVE-2022-2640
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Horner Automation's RCC 972 version 15.40
Description
The configuration files of the affected device are encrypted with weak XOR encryption, making them vulnerable to reverse engineering. This could allow an attacker to obtain credentials for running services such as File Transfer Protocol (FTP) and Hypertext Transfer Protocol (HTTP).
Recommendations
For version 15.40, consider disabling or restricting access to FTP and HTTP services until a patch or update is available to address the weak XOR encryption. As a temporary workaround, restrict access to configuration files to minimize the risk of exploitation.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rcc 972