IM
IronMonkey Threat Research

CVE-2022-29519 HIGH

Published: 2022-06-28 | Last Modified: 2024-11-21 | Status: Modified

Description

Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an adjacent attacker to login the affected products and alter device configuration settings or tamper with device firmware.

Additional Descriptions (1)

Se presenta una vulnerabilidad de transmisión de texto sin cifrar de información confidencial en STARDOM FCN Controller y FCJ Controller versiones R1.01 a R4.31, que puede permitir a un atacante adyacente iniciar sesión en los productos afectados y alterar los ajustes de configuración del dispositivo o manipular el firmware del mismo

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorADJACENT_NETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.6

Impact Score: 5.9

Base Score: 7.9 (HIGH)

AV:A/AC:M/Au:N/C:C/I:C/A:C

Access VectorADJACENT_NETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 5.5

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-319

Affected Products

Vendor Product Version Update Type
yokogawa stardom_fcj_firmware * <built-in method update of dict object at 0x7e6108beae40> Operating System
yokogawa stardom_fcn_firmware * <built-in method update of dict object at 0x7e6108beac40> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:stardom_fcj_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:stardom_fcj:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:yokogawa:stardom_fcn_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:yokogawa:stardom_fcn:-:*:*:*:*:*:*:*

References

Notification
Message here