Description
Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-34733 | Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device. |
References
| Link | Providers |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-01 |
|
History
Wed, 16 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-04-16T16:07:37.506Z
Reserved: 2022-07-19T00:00:00.000Z
Link: CVE-2022-2474
Updated: 2024-08-03T00:39:07.548Z
Status : Modified
Published: 2022-10-28T18:15:11.337
Modified: 2024-11-21T07:01:03.947
Link: CVE-2022-2474
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD