PT-2022-2833 · Hid · Hid Mercury Intelligent Controllers

Published

2022-05-23

·

Updated

2022-06-17

·

CVE-2022-31482

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 versions prior to 1.29
Description The issue is related to a buffer overflow caused by an unauthenticated HTTP request. This can lead to a segmentation fault and a denial-of-service condition, causing the device to reboot. An attacker could leverage this flaw to make the target device unresponsive, and by automating the attack, achieve a persistent denial-of-service, rendering the target controller useless.
Recommendations For versions prior to 1.29, update the firmware to version 1.29 or later to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03384
CVE-2022-31482

Affected Products

Hid Mercury Intelligent Controllers