CRITICAL🇵🇱 Wersja polska

CVE-2022-2474

CVSS 9.8v3.1pub. 2022-10-28upd. 2024-11-21

Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Haascnc Haas Controller

    HW
    Haascnc
    all versions
  • Haascnc Haas Controller Firmware

    OS
    Haascnc
    100.20.000.1110
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-2475CRITICAL9.8PL ✓same product

Niewystarczająca kontrola dostępu w Haas Controller — zapis makr poza dozwolonym zakresem

CVE-2022-41636CRITICAL9.1PL ✓same product

Haas Controller: transmisja danych w formie jawnej (cleartext)