CVE-2022-29518
Last modified
CVE-2022-29518 is a high-severity vulnerability rated 7/10 on the CVSS scale. Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 versions prior to Ver.0.1.1.3 Build01, HMI GC-A2 series(GC-A22W-CW, GC-A24W-C(W), GC-A26W-C(W), GC-A24, GC-A24-M, GC-A25, GC-A26, and GC-A26-J2), and Real time remote monitoring and control tool(Remote GC) allows a local attacker to bypass authentication due to the improper check for the Remote control setting's account names. This may allow attacker who can access the HMI from Real time remote monitoring and control tool may perform arbitrary operations on the HMI. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 versions prior to Ver.0.1.1.3 Build01, HMI GC-A2 series(GC-A22W-CW, GC-A24W-C(W), GC-A26W-C(W), GC-A24, GC-A24-M, GC-A25, GC-A26, and GC-A26-J2), and Real time remote monitoring and control tool(Remote GC) allows a local attacker to bypass authentication due to the improper check for the Remote control setting's account names. This may allow attacker who can access the HMI from Real time remote monitoring and control tool may perform arbitrary operations on the HMI. As a result, the information stored in the HMI may be disclosed, deleted or altered, and/or the equipment may be illegally operated via the HMI.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Koyoele | Remote Gc | All versions |
| Koyoele | Screen Creator Advance 2 | < 0.1.1.3 |
| Koyoele | Screen Creator Advance 2 | 0.1.1.3 |
| Koyoele | Gc-A22w-Cw Firmware | All versions |
| Koyoele | Gc-A24 Firmware | All versions |
| Koyoele | Gc-A24-M Firmware | All versions |
| Koyoele | Gc-A24w-C\(W\) Firmware | All versions |
| Koyoele | Gc-A25 Firmware | All versions |
| Koyoele | Gc-A26 Firmware | All versions |
| Koyoele | Gc-A26-J2 Firmware | All versions |
| Koyoele | Gc-A26w-C\(W\) Firmware | All versions |
References
- https://jvn.jp/en/jp/JVN50337155/index.htmlThird Party Advisory
- https://www.koyoele.co.jp/en/topics/202205095016/Vendor Advisory
- https://jvn.jp/en/jp/JVN50337155/index.htmlThird Party Advisory
- https://www.koyoele.co.jp/en/topics/202205095016/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29518?
How severe is CVE-2022-29518?
How do I fix CVE-2022-29518?
Are you affected by CVE-2022-29518?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
