Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E prior to V3.20, all versions of XGR-CPUH prior to V1.80, all versions of XGB-XBMS prior to V3.00, all versions of XGB-XBCH prior to V1.90, and all versions of XGB-XECH prior to V1.30. This would allow an attacker to identify and decrypt the password of the affected PLCs by sniffing the PLC’s communication traffic.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2022-08-31T15:33:03.944701Z

Updated: 2024-09-16T19:25:39.658Z

Reserved: 2022-08-10T00:00:00

Link: CVE-2022-2758

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-08-31T16:15:11.383

Modified: 2022-11-14T22:15:10.280

Link: CVE-2022-2758

cve-icon Redhat

No data.