CVE-2023-22804
Summary
| CVE | CVE-2023-22804 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-15 18:15:00 UTC |
| Updated | 2023-11-07 04:07:00 UTC |
| Description | LS ELECTRIC XBC-DN32U with operating system version 01.80 is missing authentication to create users on the PLC. This could allow an attacker to create and use an account with elevated privileges and take control of the device. |
Risk And Classification
Problem Types: CWE-306
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ls-electric | Xbc-dn32u | - | All | All | All |
| Operating System | Ls-electric | Xbc-dn32u Firmware | 01.80 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| LS ELECTRIC XBC-DN32U | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.