CVE-2022-2642 Vulnerability Details

  /     /     /  

CVE-2022-2642 Metadata Quick Info

CVE Published: 12/12/2022 | CVE Updated: 17/09/2024 | CVE Year: 2022
Source: icscert | Vendor: Horner Automation | Product: Remote Compact Controller (RCC) 972
Status : PUBLISHED

CVE-2022-2642 Description

Horner Automation’s RCC 972 firmware version 15.40 contains global variables. This could allow an attacker to read out sensitive values and variable keys from the device.

Metrics

CVSS Version: 3.1 | Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* NONE
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-1108
CWE Name: CWE-1108 EXCESSIVE RELIANCE ON GLOBAL VARIABLES
Source: Horner Automation

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).