PT-2022-4703 · Cognex · Cognex 3D-A1000 Dimensioning System

·

CVE-2022-1368

·

Published

2022-09-06

·

Updated

2022-09-12

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cognex 3D-A1000 Dimensioning System versions 1.0.3 and prior
Description The issue is related to missing authentication for critical functions, allowing unauthorized users to change the operator account password via web server commands. This can be achieved by monitoring web socket communications from an unauthenticated session, potentially enabling an attacker to escalate privileges to match those of the compromised account.
Recommendations For versions 1.0.3 and prior, consider disabling web server commands related to password changes until a patch is available. Restrict access to the web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05593
CVE-2022-1368

Affected Products

Cognex 3D-A1000 Dimensioning System