PT-2025-22800 · Unknown · Sipass Integrated Acc-Ap+1

Published

2025-05-23

·

Updated

2025-05-24

·

CVE-2022-31807

CVSS v4.0

5.9

Medium

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiPass integrated AC5102 (ACC-G2) (All versions) SiPass integrated ACC-AP (All versions)
Description A vulnerability has been identified where affected devices do not properly check the integrity of firmware updates. This could allow a local attacker to upload a maliciously modified firmware onto the device. In another scenario, a remote attacker who is able to intercept the transfer of a valid firmware from the server to the device could modify the firmware "on the fly".
Recommendations For SiPass integrated AC5102 (ACC-G2), ensure the integrity of firmware updates by implementing secure transfer protocols until a patch is available. For SiPass integrated ACC-AP, consider restricting access to firmware updates to minimize the risk of exploitation until a fix is provided. As a temporary workaround, consider disabling the ability to upload firmware updates directly to the devices until a secure update mechanism is implemented.

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

CVE-2022-31807

Affected Products

Sipass Integrated Ac5102
Sipass Integrated Acc-Ap