PT-2022-3241 · Hid · Hid Mercury Intelligent Controllers
Published
2022-05-23
·
Updated
2022-06-17
·
CVE-2022-31480
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 versions prior to 1.302 for the LP series and 1.296 for the EP series
Description
An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). The attacker needs to have a properly signed and encrypted binary, and loading the firmware to the device triggers a reboot. This issue is related to errors in the security mechanisms of the HID Mercury programmable logic controllers' firmware.
Recommendations
For HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 with firmware versions prior to 1.302 for the LP series and 1.296 for the EP series, update the firmware to a version that is 1.302 or later for the LP series and 1.296 or later for the EP series to resolve the issue. As a temporary workaround, consider restricting access to the firmware upload functionality to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hid Mercury Intelligent Controllers