PT-2022-3043 · Unknown · Stardom Fcn Controller
Published
2022-06-21
·
Updated
2024-08-01
·
CVE-2022-30997
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
STARDOM FCN Controller and FCJ Controller versions R4.10 through R4.31
Description
A use of hard-coded credentials issue exists, which may allow an attacker with administrative privilege to read or change configuration settings, or update the controller with tampered firmware. This could potentially give a remote attacker access to the device.
Recommendations
For versions R4.10 through R4.31, consider disabling administrative access until a patch is available to prevent exploitation of the hard-coded credentials.
Restrict access to configuration settings and firmware updates to minimize the risk of tampered firmware being installed.
Avoid using the affected controllers with administrative privileges until the issue is resolved.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stardom Fcn Controller