PT-2022-3043 · Unknown · Stardom Fcn Controller

Published

2022-06-21

·

Updated

2024-08-01

·

CVE-2022-30997

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions STARDOM FCN Controller and FCJ Controller versions R4.10 through R4.31
Description A use of hard-coded credentials issue exists, which may allow an attacker with administrative privilege to read or change configuration settings, or update the controller with tampered firmware. This could potentially give a remote attacker access to the device.
Recommendations For versions R4.10 through R4.31, consider disabling administrative access until a patch is available to prevent exploitation of the hard-coded credentials. Restrict access to configuration settings and firmware updates to minimize the risk of tampered firmware being installed. Avoid using the affected controllers with administrative privileges until the issue is resolved.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

BDU:2022-03712
CVE-2022-30997

Affected Products

Stardom Fcn Controller