CVE-2022-1318
Hills ComNav Inadequate Encryption Strength
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Hills ComNav version 3002-19 suffers from a weak communication channel. Traffic across the local network for the configuration pages can be viewed by a malicious actor. The size of certain communications packets are predictable. This would allow an attacker to learn the state of the system if they can observe the traffic. This would be possible even if the traffic were encrypted, e.g., using WPA2, as the packet sizes would remain observable. The communication encryption scheme is theoretically sound, but is not strong enough for the level of protection required.
Hills ComNav versión 3002-19 sufre de un canal de comunicación débil. El tráfico a través de la red local para las páginas de configuración puede ser visualizado por un actor malicioso. El tamaño de ciertos paquetes de comunicación es predecible. Esto permitiría a un atacante conocer el estado del sistema si puede observar el tráfico. Esto sería posible incluso si el tráfico estuviera cifrado, por ejemplo, utilizando WPA2, ya que el tamaño de los paquetes seguiría siendo observable. El esquema de encriptación de las comunicaciones es teóricamente sólido, pero no es lo suficientemente fuerte para el nivel de protección requerido
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-11 CVE Reserved
- 2022-04-20 CVE Published
- 2023-11-11 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-203: Observable Discrepancy
- CWE-326: Inadequate Encryption Strength
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.corporate.carrier.com/Images/CARR-PSA-Hills-ComNav-002-1121_tcm558-149392.pdf | 2023-07-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Carrier Search vendor "Carrier" | Hills Comnav Firmware Search vendor "Carrier" for product "Hills Comnav Firmware" | <= 3002-19 Search vendor "Carrier" for product "Hills Comnav Firmware" and version " <= 3002-19" | - |
Affected
| in | Carrier Search vendor "Carrier" | Hills Comnav Search vendor "Carrier" for product "Hills Comnav" | - | - |
Safe
|