CVE-2022-1522
Cognex 3D-A1000 Dimensioning System Improper Output Neutralization for Logs
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-117: Improper Output Neutralization for Logs, which allows an attacker to create false logs that show the password as having been changed when it is not, complicating forensics.
Cognex 3D-A1000 Dimensioning System en versión de firmware 1.0.3 (3354) y anteriores, es vulnerable a CWE-117: Neutralización Inadecuada de la Salida de los Registros, que permite a un atacante crear registros falsos que muestren que la contraseña ha sido cambiada cuando no es así, complicando los análisis forenses.
*Credits:
Tri Quach, Shanil Prasad, Brandon Park, and Nishith Sinha reported these vulnerabilities to CISA.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-04-28 CVE Reserved
- 2022-09-06 CVE Published
- 2024-08-03 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-117: Improper Output Neutralization for Logs
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-249-03 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cognex Search vendor "Cognex" | 3d-a1000 Dimensioning System Firmware Search vendor "Cognex" for product "3d-a1000 Dimensioning System Firmware" | <= 1.0.3\(3354\) Search vendor "Cognex" for product "3d-a1000 Dimensioning System Firmware" and version " <= 1.0.3\(3354\)" | - |
Affected
| in | Cognex Search vendor "Cognex" | 3d-a1000 Dimensioning System Search vendor "Cognex" for product "3d-a1000 Dimensioning System" | - | - |
Safe
|