PT-2022-4704 · Cognex · Cognex 3D-A1000 Dimensioning System

Brandon Park

+3

·

Published

2022-09-06

·

Updated

2022-09-12

·

CVE-2022-1522

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cognex 3D-A1000 Dimensioning System versions 1.0.3 (3354) and prior
Description The issue is related to improper output neutralization for logs, which can be exploited by a remote attacker to create arbitrary log files. This can lead to the creation of false logs that show the password as having been changed when it is not, complicating forensic analysis.
Recommendations For versions 1.0.3 (3354) and prior, consider disabling the logging functionality until a patch is available to prevent the creation of false logs. Restrict access to the logging module to minimize the risk of exploitation. Avoid relying on log files for password change tracking until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2022-05594
CVE-2022-1522

Affected Products

Cognex 3D-A1000 Dimensioning System