Lucene search

K
nvd[email protected]NVD:CVE-2022-32514
HistoryJan 30, 2023 - 11:15 p.m.

CVE-2022-32514

2023-01-3023:15:10
CWE-287
web.nvd.nist.gov
4
improper authentication
c-bus network automation controller
device takeover
vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.001

Percentile

45.9%

A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-Bus Automation Controller - LSS5500SHAC (Versions prior to V1.10.0), Clipsal C-Bus Network Automation Controller - 5500NAC (Versions prior to V1.10.0), Clipsal Wiser for C-Bus Automation Controller - 5500SHAC (Versions prior to V1.10.0), SpaceLogic C-Bus Network Automation Controller - 5500NAC2 (Versions prior to V1.10.0), SpaceLogic C-Bus Application Controller - 5500AC2 (Versions prior to V1.10.0)

Affected configurations

Nvd
Node
schneider-electric5500ac2Match-
AND
schneider-electric5500ac2_firmwareRange<1.11.0
Node
schneider-electric5500nacMatch-
AND
schneider-electric5500nac_firmwareRange<1.11.0
Node
schneider-electric5500nac2Match-
AND
schneider-electric5500nac2_firmwareRange<1.11.0
Node
schneider-electric5500shacMatch-
AND
schneider-electric5500shac_firmwareRange<1.11.0
Node
schneider-electriclss5500nacMatch-
AND
schneider-electriclss5500nac_firmwareRange<1.11.0
Node
schneider-electriclss5500shacMatch-
AND
schneider-electriclss5500shac_firmwareRange<1.11.0
VendorProductVersionCPE
schneider-electric5500ac2-cpe:2.3:h:schneider-electric:5500ac2:-:*:*:*:*:*:*:*
schneider-electric5500ac2_firmware*cpe:2.3:o:schneider-electric:5500ac2_firmware:*:*:*:*:*:*:*:*
schneider-electric5500nac-cpe:2.3:h:schneider-electric:5500nac:-:*:*:*:*:*:*:*
schneider-electric5500nac_firmware*cpe:2.3:o:schneider-electric:5500nac_firmware:*:*:*:*:*:*:*:*
schneider-electric5500nac2-cpe:2.3:h:schneider-electric:5500nac2:-:*:*:*:*:*:*:*
schneider-electric5500nac2_firmware*cpe:2.3:o:schneider-electric:5500nac2_firmware:*:*:*:*:*:*:*:*
schneider-electric5500shac-cpe:2.3:h:schneider-electric:5500shac:-:*:*:*:*:*:*:*
schneider-electric5500shac_firmware*cpe:2.3:o:schneider-electric:5500shac_firmware:*:*:*:*:*:*:*:*
schneider-electriclss5500nac-cpe:2.3:h:schneider-electric:lss5500nac:-:*:*:*:*:*:*:*
schneider-electriclss5500nac_firmware*cpe:2.3:o:schneider-electric:lss5500nac_firmware:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.001

Percentile

45.9%

Related for NVD:CVE-2022-32514