PT-2022-3055 · Ilc1X1+5 · Ilc1X1+15

Published

2022-06-21

·

Updated

2022-06-28

·

CVE-2022-31800

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ProConOS/ProConOS eCLR versions (affected versions not specified) AXC 1050 AXC 1050 XC AXC 3050 FC 350 PCI ETH ILC1x0 ILC1x1 ILC 1x1 GSM/GPRS ILC 3xx PC WORX RT BASIC PC WORX SRT RFC 430 ETH-IB RFC 450 ETH-IB RFC 460R PN 3TX RFC 460R PN 3TX-S RFC 470 PN 3TX RFC 470S PN 3TX RFC 480S PN 4TX
Description The issue is related to insufficient authentication of data, allowing an unauthenticated, remote attacker to upload malicious logic to devices and gain full control over them.
Recommendations For ProConOS/ProConOS eCLR, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For AXC 1050, AXC 1050 XC, AXC 3050, FC 350 PCI ETH, ILC1x0, ILC1x1, ILC 1x1 GSM/GPRS, ILC 3xx, PC WORX RT BASIC, PC WORX SRT, RFC 430 ETH-IB, RFC 450 ETH-IB, RFC 460R PN 3TX, RFC 460R PN 3TX-S, RFC 470 PN 3TX, RFC 470S PN 3TX, RFC 480S PN 4TX, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03724
CVE-2022-31800

Affected Products

Axc 1050
Axc 1050 Xc
Axc 3050
Fc 350 Pci Eth
Ilc 1X1 Gsm/Gprs
Ilc 3Xx
Ilc1X0
Ilc1X1
Pc Worx Rt Basic
Pc Worx Srt
Proconos/Proconos Eclr
Rfc 430 Eth-Ib
Rfc 450 Eth-Ib
Rfc 460R Pn 3Tx
Rfc 470S Pn 3Tx
Rfc 480S Pn 4Tx