PT-2022-17827 · Horner Automation · Rcc 972

M1Etz

·

Published

2022-12-02

·

Updated

2022-12-12

·

CVE-2022-2640

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Horner Automation's RCC 972 version 15.40
Description The configuration files of the affected device are encrypted with weak XOR encryption, making them vulnerable to reverse engineering. This could allow an attacker to obtain credentials for running services such as File Transfer Protocol (FTP) and Hypertext Transfer Protocol (HTTP).
Recommendations For version 15.40, consider disabling or restricting access to FTP and HTTP services until a patch or update is available to address the weak XOR encryption. As a temporary workaround, restrict access to configuration files to minimize the risk of exploitation.

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2022-2640

Affected Products

Rcc 972