Use of Hard-coded Cryptographic Key in Hitachi Energy products - CVE-2022-3927

 

Use of Hard-coded Cryptographic Key in Hitachi Energy products - CVE-2022-3927

Published: January 6, 2023


Vulnerability identifier: #VU70768
CSH Severity: Low
CVSS v4: 5.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2022-3927
CWE-ID: CWE-321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the target system.

The vulnerability exists due to the affected products contain public and private keys used to sign and protect custom parameter set (CPS) files from modification. A remote administrator can change the CPS file and sign it, so it is trusted as a legitimate CPS file.


Affected software

FOXMAN-UN R16A
FOXMAN-UN R15B
FOXMAN-UN R15A
FOXMAN-UN R14B
FOXMAN-UN R14A
FOXMAN-UN R11B
FOXMAN-UN R11A
FOXMAN-UN R10C
FOXMAN-UN R9C
UNEM R16A
UNEM R15B
UNEM R15A
UNEM R14B
UNEM R14A
UNEM R11B
UNEM R11A
UNEM R10C
UNEM R9C

How to mitigate CVE-2022-3927

Install updates from vendor's website.


External References

Related Security Bulletins