CVE-2022-30243
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be stored on the controller and then run without verification. A user with malicious intent can send a crafted packet to change and/or stop the program without the knowledge of other users, altering the controller's function. After the programming change, the program needs to be overwritten in order for the controller to restore its original operational function.
Honeywell Alerton Visual Logic versiones hasta 04-05-2022, permite una escritura de programación no autenticada de usuarios remotos. Esto permite que el código sea almacenado en el controlador y luego es ejecutado sin verificación. Un usuario con intenciones maliciosas puede enviar un paquete diseñado para cambiar y/o detener el programa sin el conocimiento de otros usuarios, alterando la función del controlador. Tras el cambio de programación, es necesario sobrescribir el programa para que el controlador recupere su función operativa original
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-04 CVE Reserved
- 2022-07-15 CVE Published
- 2024-05-31 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://blog.scadafence.com | Not Applicable | |
https://github.com/scadafence/Honeywell-Alerton-Vulnerabilities | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.honeywell.com/us/en/product-security | 2022-07-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Honeywell Search vendor "Honeywell" | Alterton Visual Logic Firmware Search vendor "Honeywell" for product "Alterton Visual Logic Firmware" | <= 2022-05-04 Search vendor "Honeywell" for product "Alterton Visual Logic Firmware" and version " <= 2022-05-04" | - |
Affected
| in | Honeywell Search vendor "Honeywell" | Alterton Visual Logic Search vendor "Honeywell" for product "Alterton Visual Logic" | - | - |
Safe
|