PT-2022-27682 · Unknown · Esl Protocol

Steffen Robertz

·

Published

2022-11-27

·

Updated

2023-02-17

·

CVE-2022-45914

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions ESL protocol versions (affected versions not specified)
Description The issue concerns the lack of authentication in the ESL protocol, which can be exploited by attackers to change label values using 433 MHz RF signals. This has been demonstrated in real-world scenarios, such as disrupting the organization of a hospital storage unit or altering retail pricing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2022-45914

Affected Products

Esl Protocol