2024-12-15 03:03:56 +00:00

91 lines
2.6 KiB
JSON

{
"id": "CVE-2022-2242",
"sourceIdentifier": "info@cert.vde.com",
"published": "2022-08-10T11:15:08.047",
"lastModified": "2024-11-21T07:00:36.480",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default)."
},
{
"lang": "es",
"value": "El KUKA SystemSoftware V/KSS en versiones anteriores a 8.6.5, es propenso a un control de acceso inapropiado, ya que un atacante no autorizado puede leer y escribir directamente las configuraciones del robot cuando el control de acceso no est\u00e1 disponible o no est\u00e1 habilitado (por defecto)"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "info@cert.vde.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "info@cert.vde.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:kuka:systemsoftware_v\\/kss:*:*:*:*:*:*:*:*",
"versionStartIncluding": "8.2",
"versionEndExcluding": "8.6.5",
"matchCriteriaId": "08A86D9F-4341-46E9-9F3A-492DFBAC2401"
}
]
}
]
}
],
"references": [
{
"url": "https://www.kuka.com/advisories-CVE-2022-2242",
"source": "info@cert.vde.com",
"tags": [
"Mitigation",
"Vendor Advisory"
]
},
{
"url": "https://www.kuka.com/advisories-CVE-2022-2242",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Mitigation",
"Vendor Advisory"
]
}
]
}