CVE-2022-29518
Last modified
CVE-2022-29518 is a high-severity vulnerability rated 7/10 on the CVSS scale. Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 versions prior to Ver.0.1.1.3 Build01, HMI GC-A2 series(GC-A22W-CW, GC-A24W-C(W), GC-A26W-C(W), GC-A24, GC-A24-M, GC-A25, GC-A26, and GC-A26-J2), and Real time remote monitoring and control tool(Remote GC) allows a local attacker to bypass authentication due to the improper check for the Remote control setting's account names. This may allow attacker who can access the HMI from Real time remote monitoring and control tool may perform arbitrary operations on the HMI. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 versions prior to Ver.0.1.1.3 Build01, HMI GC-A2 series(GC-A22W-CW, GC-A24W-C(W), GC-A26W-C(W), GC-A24, GC-A24-M, GC-A25, GC-A26, and GC-A26-J2), and Real time remote monitoring and control tool(Remote GC) allows a local attacker to bypass authentication due to the improper check for the Remote control setting's account names. This may allow attacker who can access the HMI from Real time remote monitoring and control tool may perform arbitrary operations on the HMI. As a result, the information stored in the HMI may be disclosed, deleted or altered, and/or the equipment may be illegally operated via the HMI.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Koyoele | Remote Gc | All versions |
| Koyoele | Screen Creator Advance 2 | < 0.1.1.3 |
| Koyoele | Screen Creator Advance 2 | 0.1.1.3 |
| Koyoele | Gc-A22w-Cw Firmware | All versions |
| Koyoele | Gc-A24 Firmware | All versions |
| Koyoele | Gc-A24-M Firmware | All versions |
| Koyoele | Gc-A24w-C\(W\) Firmware | All versions |
| Koyoele | Gc-A25 Firmware | All versions |
| Koyoele | Gc-A26 Firmware | All versions |
| Koyoele | Gc-A26-J2 Firmware | All versions |
| Koyoele | Gc-A26w-C\(W\) Firmware | All versions |
References
- https://jvn.jp/en/jp/JVN50337155/index.htmlThird Party Advisory
- https://www.koyoele.co.jp/en/topics/202205095016/Vendor Advisory
- https://jvn.jp/en/jp/JVN50337155/index.htmlThird Party Advisory
- https://www.koyoele.co.jp/en/topics/202205095016/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29518?
How severe is CVE-2022-29518?
How do I fix CVE-2022-29518?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-29512Exposure of sensitive information to an unauthorized actor i…6.5
- CVE-2022-29513Cross-site scripting vulnerability in Scheduler of Cybozu Ga…4.8
- CVE-2022-29514Improper access control in the Intel(R) SUR software before …9.8
- CVE-2022-29515Missing release of memory after effective lifetime in firmwa…5.5
- CVE-2022-29516The web console of FUJITSU Network IPCOM series (IPCOM EX2 I…9.8
- CVE-2022-29517A directory traversal vulnerability exists in the HelpdeskAc…8.8
- CVE-2022-29519Cleartext transmission of sensitive information vulnerabilit…7.5
- CVE-2022-2952GE CIMPICITY versions 2022 and prior is vulnerable when da…7.8
- CVE-2022-29520An OS command injection vulnerability exists in the console_…9.8
- CVE-2022-29522Use after free vulnerability exists in the simulator module …7.8
- CVE-2022-29523Improper conditions check in the Open CAS software maintaine…5.5
- CVE-2022-29524Out-of-bounds write vulnerability exists in V-Server v4.0.11…7.8
Are you affected by CVE-2022-29518?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
