PT-2022-17827 · Horner Automation · Rcc 972

·

CVE-2022-2640

·

Published

2022-12-02

·

Updated

2022-12-12

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Horner Automation's RCC 972 version 15.40
Description The configuration files of the affected device are encrypted with weak XOR encryption, making them vulnerable to reverse engineering. This could allow an attacker to obtain credentials for running services such as File Transfer Protocol (FTP) and Hypertext Transfer Protocol (HTTP).
Recommendations For version 15.40, consider disabling or restricting access to FTP and HTTP services until a patch or update is available to address the weak XOR encryption. As a temporary workaround, restrict access to configuration files to minimize the risk of exploitation.

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-2640

Affected Products

Rcc 972