PT-2022-2834 · Hid Mercury · Hid Mercury Intelligent Controllers

Published

2022-05-23

·

Updated

2022-06-17

·

CVE-2022-31484

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 versions prior to 1.29
Description The issue allows an unauthenticated attacker to send a specially crafted network packet to delete a user from the web interface. This could restrict access to the web interface for legitimate users, potentially requiring them to use the default user dip switch procedure to regain access. The vulnerability is related to errors in the security mechanisms of the HID Mercury programmable logic controllers' firmware.
Recommendations For versions prior to 1.29, update the firmware to version 1.29 or later to resolve the issue. As a temporary workaround, consider restricting access to the web interface to prevent exploitation until a patch is available. Avoid using the default user dip switch procedure unless necessary, as it may be required to regain access in case of an attack. At the moment, there is no information about additional mitigation measures.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03385
CVE-2022-31484

Affected Products

Hid Mercury Intelligent Controllers