← Volver a CVEs
CVE-2022-30243
HIGH8.8
Descripcion
Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be stored on the controller and then run without verification. A user with malicious intent can send a crafted packet to change and/or stop the program without the knowledge of other users, altering the controller's function. After the programming change, the program needs to be overwritten in order for the controller to restore its original operational function.
Detalles CVE
Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosLOW
Interaccion usuarioNONE
Publicado7/15/2022
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
honeywell:alterton_visual_logichoneywell:alterton_visual_logic_firmware
Debilidades (CWE)
CWE-829
Referencias
https://blog.scadafence.com(cve@mitre.org)
https://www.honeywell.com/us/en/product-security(cve@mitre.org)
https://blog.scadafence.com(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/scadafence/Honeywell-Alerton-Vulnerabilities(af854a3a-2127-422b-91ae-364da2661108)
https://www.honeywell.com/us/en/product-security(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.