PT-2022-7248 · Apsystems · Apsystems Energy Communication Unit (Ecu-C) Power Control

Published

2022-11-28

·

Updated

2023-08-08

·

CVE-2022-44037

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software versions V3.11.4, V4.1NA, V4.1SAA, W2.1NA, C1.2.2
Description An access control issue in the APsystems ENERGY COMMUNICATION UNIT (ECU-C) Power Control Software allows attackers to access sensitive data and execute specific commands and functions with full admin rights without authenticating. This enables them to perform multiple attacks, such as attacking the wireless network in the product's range. The vulnerability is also related to deficiencies in password reset code access control, which can allow a remote attacker to execute arbitrary code.
Recommendations For versions V3.11.4, V4.1NA, V4.1SAA, W2.1NA, C1.2.2, consider disabling access to sensitive data and commands until a patch is available. Restrict access to the password reset functionality to minimize the risk of exploitation. Avoid using the software with full admin rights until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-00877
CVE-2022-44037

Affected Products

Apsystems Energy Communication Unit (Ecu-C) Power Control