// For flags

CVE-2022-30262

 

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

Las RTUs de Emerson ControlWave "Next Generation" versiones hasta 02-05-2022, manejan inapropiadamente la integridad del firmware. Utilizan el protocolo BSAP-IP para transmitir las actualizaciones de firmware. Las actualizaciones de firmware son suministradas como archivos CAB que contienen una imagen binaria de firmware. En todos los casos, se ha detectado que las imágenes de firmware no tenían autenticación (en forma de firma de firmware) y sólo eran basadas en sumas de comprobación no seguras para las comprobaciones regulares de integridad.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-05-04 CVE Reserved
  • 2022-08-17 CVE Published
  • 2024-03-09 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (2)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Emerson
Search vendor "Emerson"
Controlwave Pac Firmware
Search vendor "Emerson" for product "Controlwave Pac Firmware"
<= 2022-05-02
Search vendor "Emerson" for product "Controlwave Pac Firmware" and version " <= 2022-05-02"
-
Affected
in Emerson
Search vendor "Emerson"
Controlwave Pac
Search vendor "Emerson" for product "Controlwave Pac"
--
Safe
Emerson
Search vendor "Emerson"
Controlwave Micro Firmware
Search vendor "Emerson" for product "Controlwave Micro Firmware"
<= 2022-05-02
Search vendor "Emerson" for product "Controlwave Micro Firmware" and version " <= 2022-05-02"
-
Affected
in Emerson
Search vendor "Emerson"
Controlwave Micro
Search vendor "Emerson" for product "Controlwave Micro"
--
Safe