2023-06-01 08:00:30 +00:00
{
"id" : "CVE-2022-4333" ,
"sourceIdentifier" : "info@cert.vde.com" ,
"published" : "2023-06-01T06:15:13.070" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T07:35:04.503" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-06-01 08:00:30 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "info@cert.vde.com" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 9.8 ,
"baseSeverity" : "CRITICAL" ,
2023-06-01 08:00:30 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-06-01 08:00:30 +00:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "info@cert.vde.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2023-06-01 08:00:30 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-798"
}
]
}
] ,
2023-06-09 20:00:31 +00:00
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:sprecher-automation:sprecon-e-p_dq6-1_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8CA59F65-3A20-4E7F-A888-224521DCDAFF"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:sprecher-automation:sprecon-e-p_dq6-1:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "664F4B0C-7EEE-4AAA-9C87-EA6FDAB9B10C"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:sprecher-automation:sprecon-e-p_dl6-1_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "45E23CA6-0DA8-451E-A0A8-48FD794963D9"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:sprecher-automation:sprecon-e-p_dl6-1:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FD753ACD-77BF-4F2D-AA06-5083082F9C00"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:sprecher-automation:sprecon-e-p_ds6-0_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "C7A8BB9E-BF76-475E-8A75-FC6517D07C71"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:sprecher-automation:sprecon-e-p_ds6-0:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "59815159-1AF0-4E23-94B1-040312259591"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:sprecher-automation:sprecon-e-c_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9DF00EFE-05D9-48D1-9D32-B0E4E40D14F3"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:sprecher-automation:sprecon-e-c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7DE018DD-422E-441D-8096-0AA6DC308A2A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:sprecher-automation:sprecon-e-t3_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B0BDEAF2-092F-413D-9D16-AAFA484D13AB"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:sprecher-automation:sprecon-e-t3:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A3D74929-4546-441B-8D8D-3E9F0FA7EE7E"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:sprecher-automation:sprecon-e-tc_ax-3110_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BAA3CF3D-B264-4929-BE7D-97E6415D5208"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:sprecher-automation:sprecon-e-tc_ax-3110:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "994140F8-2E5C-4CAB-8721-D91F66BCB109"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:sprecher-automation:sprecon-e_ap-2200_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "BD854646-6923-4281-A082-F5630DC0D864"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:sprecher-automation:sprecon-e_ap-2200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E7598CCB-703B-4436-AA50-88BF881795E5"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:sprecher-automation:sprecon-e_cp-2131_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "17997B66-66E7-4C68-826E-E855F8F13A8E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:sprecher-automation:sprecon-e_cp-2131:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E8F6819C-A6B1-4897-89E5-E4F6E9F2D600"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:sprecher-automation:sprecon-e_cp-2330_firmware:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1BBD5D81-18D1-4028-81BE-ED1B7CACBF61"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:sprecher-automation:sprecon-e_cp-2330:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6CEBC973-D8C2-4800-9049-C4CCA7EAF991"
}
]
}
]
}
] ,
2023-06-01 08:00:30 +00:00
"references" : [
{
"url" : "https://www.sprecher-automation.com/fileadmin/itSecurity/PDF/2022-12_Advisories.pdf" ,
2023-06-09 20:00:31 +00:00
"source" : "info@cert.vde.com" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://www.sprecher-automation.com/fileadmin/itSecurity/PDF/2022-12_Advisories.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-06-01 08:00:30 +00:00
}
]
}