Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, which could allow an attacker to obtain user credentials and gain access to system data.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-35188 Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, which could allow an attacker to obtain user credentials and gain access to system data.
Fixes

Solution

Prosys has released updates for the following products: • UA Simulation Server: Update to v5.4.0 • UA Modbus Server: Update to 1.4.20


Workaround

Prosys also recommends additional workarounds to mitigate exploitation of this vulnerability: * Restart the application after modifying user passwords. For more information, users can refer to the Prosys OPC security blog https://www.prosysopc.com/blog/#Security .

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00089}

epss

{'score': 0.00098}


Thu, 16 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-01-16T22:03:17.067Z

Reserved: 2022-08-23T15:17:49.768Z

Link: CVE-2022-2967

cve-icon Vulnrichment

Updated: 2024-08-03T00:53:00.627Z

cve-icon NVD

Status : Modified

Published: 2023-01-03T22:15:11.757

Modified: 2024-11-21T07:02:00.250

Link: CVE-2022-2967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.