CRITICAL
Advantech ADAM-3600
Published Feb 4, 2022
9.8
CRITICALCVSS 3.1
EPSS 1.21%
Description
The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.
Affected products
-
Affected
- ≥ ADAM-3600, ≤ 2.6.2
AND
- ≤ 2.6.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Advantech is aware of the issue and is currently developing a solution. For more information, contact Advantech technical support.
Advantech recommends users add their own generated SSL private key.
Weaknesses (2)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28098 Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-032-02 x_refsource_CONFIRMMitigationThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-28098 | Advisory | |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-032-02 | x_refsource_CONFIRMMitigationThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Feb 4, 2022
Updated Apr 16, 2025
Reserved Jan 27, 2022
Link CVE-2022-22987
CISA Vulnrichment
Updated Apr 16, 2025
Red Hat
No data
GitHub
No data