CVE-2022-30997
 
Severity Score
7.2
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which may allow an attacker with an administrative privilege to read/change configuration settings or update the controller with tampered firmware.
Se presenta una vulnerabilidad en el uso de credenciales embebidas en el controlador STARDOM FCN y en el controlador FCJ versiones R4.10 a R4.31, que puede permitir a un atacante con un privilegio administrativo leer/cambiar los ajustes de configuraciĆ³n o actualizar el controlador con un firmware manipulado
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-05-31 CVE Reserved
- 2022-06-28 CVE Published
- 2024-08-03 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://jvn.jp/vu/JVNVU95452299/index.html | Mitigation | |
https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-01 | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://web-material3.yokogawa.com/1/32885/files/YSAR-22-0007-E.pdf | 2024-02-13 | |
https://web-material3.yokogawa.com/19/32885/files/YSAR-22-0007-J.pdf | 2024-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Yokogawa Search vendor "Yokogawa" | Stardom Fcj Firmware Search vendor "Yokogawa" for product "Stardom Fcj Firmware" | >= r4.10 <= r4.31 Search vendor "Yokogawa" for product "Stardom Fcj Firmware" and version " >= r4.10 <= r4.31" | - |
Affected
| in | Yokogawa Search vendor "Yokogawa" | Stardom Fcj Search vendor "Yokogawa" for product "Stardom Fcj" | - | - |
Safe
|
Yokogawa Search vendor "Yokogawa" | Stardom Fcn Firmware Search vendor "Yokogawa" for product "Stardom Fcn Firmware" | >= r4.10 <= r4.31 Search vendor "Yokogawa" for product "Stardom Fcn Firmware" and version " >= r4.10 <= r4.31" | - |
Affected
| in | Yokogawa Search vendor "Yokogawa" | Stardom Fcn Search vendor "Yokogawa" for product "Stardom Fcn" | - | - |
Safe
|