CVE Published: 07/03/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: icscert |
Vendor: Power Line Communications |
Product: PLC4TRUCKS Status : PUBLISHED
CVE-2022-25922 Description
Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked by replaying J2497 messages. There is no authentication or authorization for these functions.
Metrics
CVSS Version: 3.1 |
Base Score: 6.1 MEDIUM Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H