PT-2022-3091 · Motorola · Motorola Ace1000 Rtu
Daniel Dos Santos
+1
·
Published
2022-06-22
·
Updated
2022-08-02
·
CVE-2022-30274
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Motorola ACE1000 RTU versions prior to 2022-05-02
Description
The issue is related to the use of hardcoded credentials in the XRT LAN-to-radio gateway and XNL microcode software of the Motorola ACE1000 RTU. This allows a remote attacker to gain unauthorized access to protected information. The Motorola ACE1000 RTU uses ECB encryption unsafely, storing credentials encrypted with the Tiny Encryption Algorithm (TEA) in ECB mode using a hardcoded key. This affects communication with the XRT LAN-to-radio gateway and authentication to the XNL port.
Recommendations
For Motorola ACE1000 RTU versions prior to 2022-05-02, consider disabling the use of hardcoded credentials for the XRT LAN-to-radio gateway and XNL port until a patch is available. Restrict access to the XNL port to minimize the risk of exploitation. Avoid using the hardcoded key for TEA encryption in ECB mode until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Motorola Ace1000 Rtu