CVE-2022-2640

The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol (FTP) and Hypertext Transfer Protocol (HTTP).
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-335-02 Patch Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hornerautomation:rcc972_firmware:15.40:*:*:*:*:*:*:*
cpe:2.3:h:hornerautomation:rcc972:-:*:*:*:*:*:*:*

History

06 Dec 2022, 12:32

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-335-02 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-335-02 - Patch, Third Party Advisory, US Government Resource
First Time Hornerautomation rcc972 Firmware
Hornerautomation
Hornerautomation rcc972
CPE cpe:2.3:h:hornerautomation:rcc972:-:*:*:*:*:*:*:*
cpe:2.3:o:hornerautomation:rcc972_firmware:15.40:*:*:*:*:*:*:*

02 Dec 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-02 20:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-2640

Mitre link : CVE-2022-2640

CVE.ORG link : CVE-2022-2640


JSON object : View

Products Affected

hornerautomation

  • rcc972
  • rcc972_firmware
CWE
CWE-326

Inadequate Encryption Strength