#VU67057 Missing Authentication for Critical Function in 3D-A1000 Dimensioning System


Published: 2022-09-07

Vulnerability identifier: #VU67057

Vulnerability risk: High

CVSSv3.1: 8.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-1368

CWE-ID: CWE-306

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
3D-A1000 Dimensioning System
Hardware solutions / Security hardware applicances

Vendor: Cognex Corporation

Description

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to missing authentication for critical function. A remote attacker can change the operator account password via webserver commands by monitoring web socket communications from an unauthenticated session and gain elevated privileges on the target system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

3D-A1000 Dimensioning System: 1.0.3 3354


External links
http://www.cisa.gov/uscert/ics/advisories/icsa-22-249-03


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability