PT-2025-22800 · Unknown · Sipass Integrated Acc-Ap+1
Published
2025-05-23
·
Updated
2025-05-24
·
CVE-2022-31807
CVSS v4.0
5.9
Medium
| Vector | AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SiPass integrated AC5102 (ACC-G2) (All versions)
SiPass integrated ACC-AP (All versions)
Description
A vulnerability has been identified where affected devices do not properly check the integrity of firmware updates. This could allow a local attacker to upload a maliciously modified firmware onto the device. In another scenario, a remote attacker who is able to intercept the transfer of a valid firmware from the server to the device could modify the firmware "on the fly".
Recommendations
For SiPass integrated AC5102 (ACC-G2), ensure the integrity of firmware updates by implementing secure transfer protocols until a patch is available.
For SiPass integrated ACC-AP, consider restricting access to firmware updates to minimize the risk of exploitation until a fix is provided.
As a temporary workaround, consider disabling the ability to upload firmware updates directly to the devices until a secure update mechanism is implemented.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sipass Integrated Ac5102
Sipass Integrated Acc-Ap