Cryptographic issues in APC products - CVE-2022-0715
Published: March 9, 2022 / Updated: March 15, 2022
Vulnerability identifier: #VU61213
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0715
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to flaw in firmware upgrade mechanisms. A remote attacker can perform unsigned firmware upgrade and execute arbitrary code on the system.
Affected software
SMT Series
SMC Series
SRT Series
SMTL Series
SCL Series
SMX Series
SMC Series
SRT Series
SMTL Series
SCL Series
SMX Series
How to mitigate CVE-2022-0715
Install update from vendor's website.