PT-2022-17832 · Horner Automation · Rcc 972

M1Etz

·

Published

2022-12-02

·

Updated

2022-12-12

·

CVE-2022-2642

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Horner Automation’s RCC 972 firmware version 15.40
Description The issue concerns the presence of global variables in the firmware, which could allow an attacker to read out sensitive values and variable keys from the device.
Recommendations For version 15.40, consider restricting access to the device to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2022-2642

Affected Products

Rcc 972