cve/2022/CVE-2022-2242.md

18 lines
792 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-2242](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2242)
![](https://img.shields.io/static/v1?label=Product&message=SystemSoftware%20V%2FKSS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=8.2%3C%208.6.5%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-306%20Missing%20Authentication%20for%20Critical%20Function&color=brighgreen)
### Description
The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default).
### POC
#### Reference
- https://www.kuka.com/advisories-CVE-2022-2242
#### Github
No PoCs found on GitHub currently.