Cryptographic issues in APC products - CVE-2022-0715

 

Cryptographic issues in APC products - CVE-2022-0715

Published: March 9, 2022 / Updated: March 15, 2022


Vulnerability identifier: #VU61213
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-0715
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to flaw in firmware upgrade mechanisms. A remote attacker can perform unsigned firmware upgrade and execute arbitrary code on the system.


Affected software

SMT Series
SMC Series
SRT Series
SMTL Series
SCL Series
SMX Series

How to mitigate CVE-2022-0715

Install update from vendor's website.


External References

Related Security Bulletins