Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to
attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication.
attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-40944 | Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication. |
Fixes
Solution
Daikin Holdings Singapore Pte Ltd. has released an update that will automatically install if the SVM controller is enabled. No user operation is required.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-284-02 |
|
History
Wed, 16 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-04-16T16:04:52.712Z
Reserved: 2022-09-29T14:08:03.143Z
Link: CVE-2022-38355
Updated: 2024-08-03T10:54:03.383Z
Status : Modified
Published: 2022-12-13T22:15:10.090
Modified: 2024-11-21T07:16:19.087
Link: CVE-2022-38355
No data.
OpenCVE Enrichment
No data.
EUVD