PT-2022-18501 · Ls Electric · Xgr-Cpuh+6

Hong-Gi Kin

·

Published

2022-08-31

·

Updated

2022-11-14

·

CVE-2022-2758

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LS Electric XG5000 software versions prior to V4.0 LS Electric PLCs: XGK-CPUU/H/A/S/E versions prior to V3.50 XGI-CPUU/UD/H/S/E versions prior to V3.20 XGR-CPUH versions prior to V1.80 XGB-XBMS versions prior to V3.00 XGB-XBCH versions prior to V1.90 XGB-XECH versions prior to V1.30
Description The issue concerns inadequate encryption of passwords during communication between the LS Electric XG5000 software and the affected PLCs. This allows an attacker to identify and decrypt the password of the affected PLCs by sniffing the PLC's communication traffic.
Recommendations For LS Electric XG5000 software versions prior to V4.0, update to version V4.0 or later. For XGK-CPUU/H/A/S/E versions prior to V3.50, update to version V3.50 or later. For XGI-CPUU/UD/H/S/E versions prior to V3.20, update to version V3.20 or later. For XGR-CPUH versions prior to V1.80, update to version V1.80 or later. For XGB-XBMS versions prior to V3.00, update to version V3.00 or later. For XGB-XBCH versions prior to V1.90, update to version V1.90 or later. For XGB-XECH versions prior to V1.30, update to version V1.30 or later.

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2022-2758

Affected Products

Ls Electric Xg5000
Xgb-Xbch
Xgb-Xbms
Xgb-Xech
Xgi-Cpuu/Ud/H/S/E
Xgk-Cpuu/H/A/S/E
Xgr-Cpuh