PT-2022-4704 · Cognex · Cognex 3D-A1000 Dimensioning System
Brandon Park
+3
·
Published
2022-09-06
·
Updated
2022-09-12
·
CVE-2022-1522
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cognex 3D-A1000 Dimensioning System versions 1.0.3 (3354) and prior
Description
The issue is related to improper output neutralization for logs, which can be exploited by a remote attacker to create arbitrary log files. This can lead to the creation of false logs that show the password as having been changed when it is not, complicating forensic analysis.
Recommendations
For versions 1.0.3 (3354) and prior, consider disabling the logging functionality until a patch is available to prevent the creation of false logs.
Restrict access to the logging module to minimize the risk of exploitation.
Avoid relying on log files for password change tracking until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cognex 3D-A1000 Dimensioning System