PT-2022-2833 · Hid · Hid Mercury Intelligent Controllers
Published
2022-05-23
·
Updated
2022-06-17
·
CVE-2022-31482
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 versions prior to 1.29
Description
The issue is related to a buffer overflow caused by an unauthenticated HTTP request. This can lead to a segmentation fault and a denial-of-service condition, causing the device to reboot. An attacker could leverage this flaw to make the target device unresponsive, and by automating the attack, achieve a persistent denial-of-service, rendering the target controller useless.
Recommendations
For versions prior to 1.29, update the firmware to version 1.29 or later to resolve the issue.
As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hid Mercury Intelligent Controllers