#VU64582 Insufficient verification of data authenticity in JTEKT Corporation products - CVE-2022-29958
Published: June 22, 2022
Vulnerability identifier: #VU64582
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2022-29958
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
TOYOPUC PC10G-CPU TCC-6353
TOYOPUC PC10GE TCC-6464
TOYOPUC PC10P TCC-6372
TOYOPUC PC10P-DP TCC-6726
TOYOPUC PC10P-DP-IO TCC-6752
TOYOPUC PC10B-P TCC-6373
TOYOPUC PC10B TCC-1021
TOYOPUC PC10E TCC-4737
TOYOPUC PC10EL TCC-4747
TOYOPUC Plus CPU TCC-6740
TOYOPUC PC3JX TCC-6901
TOYOPUC PC3JX-D TCC-6902
TOYOPUC PC10PE TCC-1101
TOYOPUC PC10PE-1616P TCC-1102
TOYOPUC PCDL TKC-6688
TOYOPUC Nano 10GX TUC-1157
TOYOPUC Nano CPU TUC-6941
TOYOPUC PC10G-CPU TCC-6353
TOYOPUC PC10GE TCC-6464
TOYOPUC PC10P TCC-6372
TOYOPUC PC10P-DP TCC-6726
TOYOPUC PC10P-DP-IO TCC-6752
TOYOPUC PC10B-P TCC-6373
TOYOPUC PC10B TCC-1021
TOYOPUC PC10E TCC-4737
TOYOPUC PC10EL TCC-4747
TOYOPUC Plus CPU TCC-6740
TOYOPUC PC3JX TCC-6901
TOYOPUC PC3JX-D TCC-6902
TOYOPUC PC10PE TCC-1101
TOYOPUC PC10PE-1616P TCC-1102
TOYOPUC PCDL TKC-6688
TOYOPUC Nano 10GX TUC-1157
TOYOPUC Nano CPU TUC-6941
Software vendor:
JTEKT Corporation
JTEKT Corporation
Description
The vulnerability allows a remote attacker to compromsie the target system.
The vulnerability exists due to the affected product lacks privilege separation capabilities. A remote attacker can execute arbitrary machine code.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.