CVE-2022-2640
Summary
| CVE | CVE-2022-2640 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-02 20:15:00 UTC |
| Updated | 2022-12-06 12:32:00 UTC |
| Description | The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol (FTP) and Hypertext Transfer Protocol (HTTP). |
Risk And Classification
Problem Types: CWE-326
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Hornerautomation | Rcc972 | - | All | All | All |
| Operating System | Hornerautomation | Rcc972 Firmware | 15.40 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Horner Automation Remote Compact Controller | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: m1etz reported these vulnerabilities through the Computer Emergency Response Team, CERT-Bund, to CISA
Legacy QID Mappings
- 591343 Horner Automation Remote Compact Controller Inadequate Encryption Strength, Use of Hard-coded Cryptographic Key, Excessive Reliance on Global Variables Multiple Vulnerabilities (ICSA-22-335-02)