CVE-2022-2474
Last modified
CVE-2022-2474 is a high-severity vulnerability rated 8/10 on the CVSS scale. Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device.. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Haascnc | Haas Controller Firmware | 100.20.000.1110 |
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-01Third Party Advisory, US Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-298-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2474?
How severe is CVE-2022-2474?
How do I fix CVE-2022-2474?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-24734MyBB is a free and open source forum software. In affected v…7.2
- CVE-2022-24735Redis is an in-memory database that persists on disk. By exp…7.8
- CVE-2022-24736Redis is an in-memory database that persists on disk. Prior …5.5
- CVE-2022-24737HTTPie is a command-line HTTP client. HTTPie has the practic…6.5
- CVE-2022-24738Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmo…7.4
- CVE-2022-24739alltube is an html front end for youtube-dl. On releases pri…6.1
- CVE-2022-24740Volto is a ReactJS-based frontend for the Plone Content Mana…7.5
- CVE-2022-24741Nextcloud server is an open source, self hosted cloud style …6.5
- CVE-2022-24742Sylius is an open source eCommerce platform. Prior to versio…5.5
- CVE-2022-24743Sylius is an open source eCommerce platform. Prior to versio…8.2
- CVE-2022-24744Shopware is an open commerce platform based on the Symfony p…3.5
- CVE-2022-24745Shopware is an open commerce platform based on the Symfony p…6.5
Are you affected by CVE-2022-2474?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
