// For flags

CVE-2022-31480

Unauthenticated Firmware Upload and Arbitrary Reboot

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An unauthenticated attacker could arbitrarily upload firmware files to the target device, ultimately causing a Denial-of-Service (DoS). This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The attacker needs to have a properly signed and encrypted binary, loading the firmware to the device ultimately triggers a reboot.

Un atacante no autenticado podría cargar arbitrariamente archivos de firmware en el dispositivo objetivo, causando en última instancia una denegación de servicio (DoS). Esta vulnerabilidad afecta a los productos basados en los controladores inteligentes HID Mercury LP1501, LP1502, LP2500, LP4502 y EP4502 que contienen versiones de firmware anteriores a 1.302 para la serie LP y 1.296 para la serie EP. El atacante necesita tener un binario debidamente firmado y encriptado, la carga del firmware en el dispositivo finalmente desencadena un reinicio

*Credits: Sam Quinn @eAyeP and Steve Povolny @spovolny from Trellix Threat Labs
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-05-23 CVE Reserved
  • 2022-06-06 CVE Published
  • 2023-11-17 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-425: Direct Request ('Forced Browsing')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hidglobal
Search vendor "Hidglobal"
Lp1501 Firmware
Search vendor "Hidglobal" for product "Lp1501 Firmware"
< 1.302
Search vendor "Hidglobal" for product "Lp1501 Firmware" and version " < 1.302"
-
Affected
in Hidglobal
Search vendor "Hidglobal"
Lp1501
Search vendor "Hidglobal" for product "Lp1501"
--
Safe
Hidglobal
Search vendor "Hidglobal"
Lp1502 Firmware
Search vendor "Hidglobal" for product "Lp1502 Firmware"
< 1.302
Search vendor "Hidglobal" for product "Lp1502 Firmware" and version " < 1.302"
-
Affected
in Hidglobal
Search vendor "Hidglobal"
Lp1502
Search vendor "Hidglobal" for product "Lp1502"
--
Safe
Hidglobal
Search vendor "Hidglobal"
Lp2500 Firmware
Search vendor "Hidglobal" for product "Lp2500 Firmware"
< 1.302
Search vendor "Hidglobal" for product "Lp2500 Firmware" and version " < 1.302"
-
Affected
in Hidglobal
Search vendor "Hidglobal"
Lp2500
Search vendor "Hidglobal" for product "Lp2500"
--
Safe
Hidglobal
Search vendor "Hidglobal"
Lp4502 Firmware
Search vendor "Hidglobal" for product "Lp4502 Firmware"
< 1.302
Search vendor "Hidglobal" for product "Lp4502 Firmware" and version " < 1.302"
-
Affected
in Hidglobal
Search vendor "Hidglobal"
Lp4502
Search vendor "Hidglobal" for product "Lp4502"
--
Safe
Hidglobal
Search vendor "Hidglobal"
Ep4502 Firmware
Search vendor "Hidglobal" for product "Ep4502 Firmware"
< 1.296
Search vendor "Hidglobal" for product "Ep4502 Firmware" and version " < 1.296"
-
Affected
in Hidglobal
Search vendor "Hidglobal"
Ep4502
Search vendor "Hidglobal" for product "Ep4502"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 Lnl-4420 Firmware
Search vendor "Carrier" for product "Lenels2 Lnl-4420 Firmware"
< 1.296
Search vendor "Carrier" for product "Lenels2 Lnl-4420 Firmware" and version " < 1.296"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 Lnl-4420
Search vendor "Carrier" for product "Lenels2 Lnl-4420"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 Lnl-x2210 Firmware
Search vendor "Carrier" for product "Lenels2 Lnl-x2210 Firmware"
< 1.302
Search vendor "Carrier" for product "Lenels2 Lnl-x2210 Firmware" and version " < 1.302"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 Lnl-x2210
Search vendor "Carrier" for product "Lenels2 Lnl-x2210"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 Lnl-x2220 Firmware
Search vendor "Carrier" for product "Lenels2 Lnl-x2220 Firmware"
< 1.302
Search vendor "Carrier" for product "Lenels2 Lnl-x2220 Firmware" and version " < 1.302"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 Lnl-x2220
Search vendor "Carrier" for product "Lenels2 Lnl-x2220"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 Lnl-x3300 Firmware
Search vendor "Carrier" for product "Lenels2 Lnl-x3300 Firmware"
< 1.302
Search vendor "Carrier" for product "Lenels2 Lnl-x3300 Firmware" and version " < 1.302"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 Lnl-x3300
Search vendor "Carrier" for product "Lenels2 Lnl-x3300"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 Lnl-x4420 Firmware
Search vendor "Carrier" for product "Lenels2 Lnl-x4420 Firmware"
< 1.302
Search vendor "Carrier" for product "Lenels2 Lnl-x4420 Firmware" and version " < 1.302"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 Lnl-x4420
Search vendor "Carrier" for product "Lenels2 Lnl-x4420"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 S2-lp-1501 Firmware
Search vendor "Carrier" for product "Lenels2 S2-lp-1501 Firmware"
< 1.302
Search vendor "Carrier" for product "Lenels2 S2-lp-1501 Firmware" and version " < 1.302"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 S2-lp-1501
Search vendor "Carrier" for product "Lenels2 S2-lp-1501"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 S2-lp-1502 Firmware
Search vendor "Carrier" for product "Lenels2 S2-lp-1502 Firmware"
< 1.302
Search vendor "Carrier" for product "Lenels2 S2-lp-1502 Firmware" and version " < 1.302"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 S2-lp-1502
Search vendor "Carrier" for product "Lenels2 S2-lp-1502"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 S2-lp-2500 Firmware
Search vendor "Carrier" for product "Lenels2 S2-lp-2500 Firmware"
< 1.302
Search vendor "Carrier" for product "Lenels2 S2-lp-2500 Firmware" and version " < 1.302"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 S2-lp-2500
Search vendor "Carrier" for product "Lenels2 S2-lp-2500"
--
Safe
Carrier
Search vendor "Carrier"
Lenels2 S2-lp-4502 Firmware
Search vendor "Carrier" for product "Lenels2 S2-lp-4502 Firmware"
< 1.302
Search vendor "Carrier" for product "Lenels2 S2-lp-4502 Firmware" and version " < 1.302"
-
Affected
in Carrier
Search vendor "Carrier"
Lenels2 S2-lp-4502
Search vendor "Carrier" for product "Lenels2 S2-lp-4502"
--
Safe