The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-28098 The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.
Fixes

Solution

No solution given by the vendor.


Workaround

Advantech is aware of the issue and is currently developing a solution. For more information, contact Advantech technical support. Advantech recommends users add their own generated SSL private key.

History

Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:46:12.102Z

Reserved: 2022-01-27T00:00:00.000Z

Link: CVE-2022-22987

cve-icon Vulnrichment

Updated: 2024-08-03T03:28:42.705Z

cve-icon NVD

Status : Modified

Published: 2022-02-04T23:15:13.437

Modified: 2024-11-21T06:47:44.890

Link: CVE-2022-22987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.