Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p4gj-rmqv-7h27

Опубликовано: 27 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

EPSS

Процентиль: 27%
0.00093
Низкий

8.8 High

CVSS3

Дефекты

CWE-345

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

oracle-oval
почти 3 года назад

ELSA-2022-17957: ol8addon security update (IMPORTANT)

EPSS

Процентиль: 27%
0.00093
Низкий

8.8 High

CVSS3

Дефекты

CWE-345