Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to

attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-40944 Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication.
Fixes

Solution

Daikin Holdings Singapore Pte Ltd. has released an update that will automatically install if the SVM controller is enabled. No user operation is required.


Workaround

No workaround given by the vendor.

History

Wed, 16 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:04:52.712Z

Reserved: 2022-09-29T14:08:03.143Z

Link: CVE-2022-38355

cve-icon Vulnrichment

Updated: 2024-08-03T10:54:03.383Z

cve-icon NVD

Status : Modified

Published: 2022-12-13T22:15:10.090

Modified: 2024-11-21T07:16:19.087

Link: CVE-2022-38355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.