PT-2022-2834 · Hid Mercury · Hid Mercury Intelligent Controllers
Published
2022-05-23
·
Updated
2022-06-17
·
CVE-2022-31484
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 versions prior to 1.29
Description
The issue allows an unauthenticated attacker to send a specially crafted network packet to delete a user from the web interface. This could restrict access to the web interface for legitimate users, potentially requiring them to use the default user dip switch procedure to regain access. The vulnerability is related to errors in the security mechanisms of the HID Mercury programmable logic controllers' firmware.
Recommendations
For versions prior to 1.29, update the firmware to version 1.29 or later to resolve the issue.
As a temporary workaround, consider restricting access to the web interface to prevent exploitation until a patch is available.
Avoid using the default user dip switch procedure unless necessary, as it may be required to regain access in case of an attack.
At the moment, there is no information about additional mitigation measures.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hid Mercury Intelligent Controllers