Lucene search

K
cvelistSchneiderCVELIST:CVE-2022-32514
HistoryJan 30, 2023 - 12:00 a.m.

CVE-2022-32514

2023-01-3000:00:00
CWE-287
schneider
www.cve.org
cve-2022-32514
cwe-287
c-bus network automation controller
wiser for c-bus automation controller
clipsal c-bus network automation controller
spacelogic c-bus network automation controller

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.1%

A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-Bus Automation Controller - LSS5500SHAC (Versions prior to V1.10.0), Clipsal C-Bus Network Automation Controller - 5500NAC (Versions prior to V1.10.0), Clipsal Wiser for C-Bus Automation Controller - 5500SHAC (Versions prior to V1.10.0), SpaceLogic C-Bus Network Automation Controller - 5500NAC2 (Versions prior to V1.10.0), SpaceLogic C-Bus Application Controller - 5500AC2 (Versions prior to V1.10.0)

CNA Affected

[
  {
    "vendor": "Schneider Electric",
    "product": "C-Bus Network Automation Controller, LSS5500NAC",
    "versions": [
      {
        "version": "All",
        "status": "affected",
        "lessThan": "V1.10.0",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Schneider Electric",
    "product": "Wiser for C-Bus Automation Controller, LSS5500SHAC",
    "versions": [
      {
        "version": "All ",
        "status": "affected",
        "lessThan": "V1.10.0",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Schneider Electric",
    "product": "Clipsal C-Bus Network Automation Controller, 5500NAC",
    "versions": [
      {
        "version": "All ",
        "status": "affected",
        "lessThan": "V1.10.0",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Schneider Electric",
    "product": "Clipsal Wiser for C-Bus Automation Controller, 5500SHAC",
    "versions": [
      {
        "version": "All ",
        "status": "affected",
        "lessThan": "V1.10.0",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Schneider Electric",
    "product": "SpaceLogic C-Bus Network Automation Controller, 5500NAC2",
    "versions": [
      {
        "version": "All",
        "status": "affected",
        "lessThan": "V1.10.0",
        "versionType": "custom"
      }
    ]
  },
  {
    "vendor": "Schneider Electric",
    "product": "SpaceLogic C-Bus Application Controller, 5500AC2",
    "versions": [
      {
        "version": "All",
        "status": "affected",
        "lessThan": "V1.10.0",
        "versionType": "custom"
      }
    ]
  }
]

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

44.1%

Related for CVELIST:CVE-2022-32514