CVE-2022-31481

Summary

CVECVE-2022-31481
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2022-06-06 17:15:00 UTC
Updated2022-06-17 14:31:00 UTC
DescriptionAn unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The overflowed data can allow the attacker to manipulate the “normal” code execution to that of their choosing. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable.

Risk And Classification

Problem Types: CWE-120

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Carrier Lenels2 Lnl-4420 - All All All
Operating System Carrier Lenels2 Lnl-4420 Firmware All All All All
Hardware Carrier Lenels2 Lnl-x2210 - All All All
Operating System Carrier Lenels2 Lnl-x2210 Firmware All All All All
Hardware Carrier Lenels2 Lnl-x2220 - All All All
Operating System Carrier Lenels2 Lnl-x2220 Firmware All All All All
Hardware Carrier Lenels2 Lnl-x3300 - All All All
Operating System Carrier Lenels2 Lnl-x3300 Firmware All All All All
Hardware Carrier Lenels2 Lnl-x4420 - All All All
Operating System Carrier Lenels2 Lnl-x4420 Firmware All All All All
Hardware Carrier Lenels2 S2-lp-1501 - All All All
Operating System Carrier Lenels2 S2-lp-1501 Firmware All All All All
Hardware Carrier Lenels2 S2-lp-1502 - All All All
Operating System Carrier Lenels2 S2-lp-1502 Firmware All All All All
Hardware Carrier Lenels2 S2-lp-2500 - All All All
Operating System Carrier Lenels2 S2-lp-2500 Firmware All All All All
Hardware Carrier Lenels2 S2-lp-4502 - All All All
Operating System Carrier Lenels2 S2-lp-4502 Firmware All All All All
Hardware Hidglobal Ep4502 - All All All
Operating System Hidglobal Ep4502 Firmware All All All All
Hardware Hidglobal Lp1501 - All All All
Operating System Hidglobal Lp1501 Firmware All All All All
Hardware Hidglobal Lp1502 - All All All
Operating System Hidglobal Lp1502 Firmware All All All All
Hardware Hidglobal Lp2500 - All All All
Operating System Hidglobal Lp2500 Firmware All All All All
Hardware Hidglobal Lp4502 - All All All
Operating System Hidglobal Lp4502 Firmware All All All All

References

ReferenceSourceLinkTags
Advisories & Resources | Product Security | Carrier Corporate MISC www.corporate.carrier.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Vendor Comments And Credit

Discovery Credit

LEGACY: Sam Quinn @eAyeP and Steve Povolny @spovolny from Trellix Threat Labs

Legacy QID Mappings

  • 590928 Carrier LenelS2 HID Mercury access panels Multiple Vulnerabilities (ICSA-22-153-01)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report