CVE-2022-2758

MEDIUMCVSS 5.9/10EPSS 0.31%

Last modified

CVE-2022-2758 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E prior to V3.20, all versions of XGR-CPUH prior to V1.80, all versions of XGB-XBMS prior to V3.00, all versions of XGB-XBCH prior to V1.90, and all versions of XGB-XECH prior to V1.30. EPSS estimates a 0.31% chance of exploitation in the next 30 days.

Description

Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E prior to V3.20, all versions of XGR-CPUH prior to V1.80, all versions of XGB-XBMS prior to V3.00, all versions of XGB-XBCH prior to V1.90, and all versions of XGB-XECH prior to V1.30. This would allow an attacker to identify and decrypt the password of the affected PLCs by sniffing the PLC’s communication traffic.

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.31%

22.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Ls-ElectricXg5000All versions
Ls-ElectricXgk-Cpuun FirmwareAll versions
Ls-ElectricXgk-Cpuhn FirmwareAll versions
Ls-ElectricXgk-Cpusn FirmwareAll versions
Ls-ElectricXgk-Cpuu FirmwareAll versions
Ls-ElectricXgk-Cpuh FirmwareAll versions
Ls-ElectricXgk-Cpua FirmwareAll versions
Ls-ElectricXgk-Cpus FirmwareAll versions
Ls-ElectricXgk-Cpue FirmwareAll versions
Ls-ElectricXgi-Cpuun FirmwareAll versions
Ls-ElectricXgi-Cpuu FirmwareAll versions
Ls-ElectricXgi-Cpuh FirmwareAll versions
Ls-ElectricXgi-Cpus FirmwareAll versions
Ls-ElectricXgi-Cpue FirmwareAll versions
Ls-ElectricXgr-Cpuh\/F FirmwareAll versions
Ls-ElectricXgr-Cpuh\/T FirmwareAll versions
Ls-ElectricXgr-Cpuh\/S FirmwareAll versions
Ls-ElectricXgi-D21a FirmwareAll versions
Ls-ElectricXgi-D22a FirmwareAll versions
Ls-ElectricXgi-D22b FirmwareAll versions
Ls-ElectricXgi-D24a FirmwareAll versions
Ls-ElectricXgi-D24b FirmwareAll versions
Ls-ElectricXgi-D28a FirmwareAll versions
Ls-ElectricXgi-D28b FirmwareAll versions
Ls-ElectricXgi-A12a FirmwareAll versions
Ls-ElectricXgi-A21a FirmwareAll versions
Ls-ElectricXgi-A21c FirmwareAll versions
Ls-ElectricXgq-Ry1a FirmwareAll versions
Ls-ElectricXgq-Ry2a FirmwareAll versions
Ls-ElectricXgq-Ry2b FirmwareAll versions
Ls-ElectricXgq-Tr1c FirmwareAll versions
Ls-ElectricXgq-Tr2a FirmwareAll versions
Ls-ElectricXgq-Tr2b FirmwareAll versions
Ls-ElectricXgq-Tr4a FirmwareAll versions
Ls-ElectricXgq-Tr4b FirmwareAll versions
Ls-ElectricXgq-Tr8a FirmwareAll versions
Ls-ElectricXgq-Tr8b FirmwareAll versions
Ls-ElectricXgq-Ss2a FirmwareAll versions
Ls-ElectricXgf-Av8a FirmwareAll versions
Ls-ElectricXgf-Ac8a FirmwareAll versions
Ls-ElectricXgf-Ad16a FirmwareAll versions
Ls-ElectricXgf-Aw4s FirmwareAll versions
Ls-ElectricXgf-Dv4a FirmwareAll versions
Ls-ElectricXgf-Dc4a FirmwareAll versions
Ls-ElectricXgf-Dv8a FirmwareAll versions
Ls-ElectricXgf-Dc8a FirmwareAll versions
Ls-ElectricXgf-Dv4s FirmwareAll versions
Ls-ElectricXgf-Dc4s FirmwareAll versions
Ls-ElectricXgf-Ah6a FirmwareAll versions
Ls-ElectricXgf-Tc4s FirmwareAll versions

Showing 50 of 235 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-2758?
Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E prior to V3.20, all versions of XGR-CPUH prior to V1.80, all versions of XGB-XBMS prior to V3.00, all versions of XGB-XBCH prior to V1.90, and all versions of XGB-XECH prior to V1.30. This would allow an attacker to identify and decrypt the password of the affected PLCs by sniffing the PLC’s communication traffic.
How severe is CVE-2022-2758?
CVE-2022-2758 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 0.31% probability of exploitation in the next 30 days.
How do I fix CVE-2022-2758?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-2758?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST