PT-2022-18501 · Ls Electric · Xgr-Cpuh+6
Hong-Gi Kin
·
Published
2022-08-31
·
Updated
2022-11-14
·
CVE-2022-2758
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LS Electric XG5000 software versions prior to V4.0
LS Electric PLCs:
XGK-CPUU/H/A/S/E versions prior to V3.50
XGI-CPUU/UD/H/S/E versions prior to V3.20
XGR-CPUH versions prior to V1.80
XGB-XBMS versions prior to V3.00
XGB-XBCH versions prior to V1.90
XGB-XECH versions prior to V1.30
Description
The issue concerns inadequate encryption of passwords during communication between the LS Electric XG5000 software and the affected PLCs. This allows an attacker to identify and decrypt the password of the affected PLCs by sniffing the PLC's communication traffic.
Recommendations
For LS Electric XG5000 software versions prior to V4.0, update to version V4.0 or later.
For XGK-CPUU/H/A/S/E versions prior to V3.50, update to version V3.50 or later.
For XGI-CPUU/UD/H/S/E versions prior to V3.20, update to version V3.20 or later.
For XGR-CPUH versions prior to V1.80, update to version V1.80 or later.
For XGB-XBMS versions prior to V3.00, update to version V3.00 or later.
For XGB-XBCH versions prior to V1.90, update to version V1.90 or later.
For XGB-XECH versions prior to V1.30, update to version V1.30 or later.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ls Electric Xg5000
Xgb-Xbch
Xgb-Xbms
Xgb-Xech
Xgi-Cpuu/Ud/H/S/E
Xgk-Cpuu/H/A/S/E
Xgr-Cpuh