CRITICAL
KUKA V/KSS WoV SH access control vulnerability
Published Aug 10, 2022
9.8
CRITICALCVSS 3.1
EPSS 1.18%
Description
The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default).
Affected products
-
- Version 8.2StatusaffectedConstraints<8.6.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| KUKA | SystemSoftware V/KSS | n/a |
|
- ≥ 8.2 · < 8.6.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-34520 Advisory
- https://www.kuka.com/advisories-CVE-2022-2242 x_refsource_CONFIRMMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-34520 | Advisory | |
| https://www.kuka.com/advisories-CVE-2022-2242 | x_refsource_CONFIRMMitigationVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERTVDE
Published Aug 10, 2022
Updated Sep 17, 2024
Reserved Jun 28, 2022
Link CVE-2022-2242
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-34520 Assigner CERTVDE
Published Aug 10, 2022
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2022-34520