PT-2022-27682 · Unknown · Esl Protocol
Steffen Robertz
·
Published
2022-11-27
·
Updated
2023-02-17
·
CVE-2022-45914
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ESL protocol versions (affected versions not specified)
Description
The issue concerns the lack of authentication in the ESL protocol, which can be exploited by attackers to change label values using 433 MHz RF signals. This has been demonstrated in real-world scenarios, such as disrupting the organization of a hospital storage unit or altering retail pricing.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Esl Protocol