Haas Controller version 100.20.000.1110 has insufficient granularity of access control...
Vulnerability Description
Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the authorized accessible range. This could allow a user to access privileged resources or resources out of context.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-2475
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Marco Balduzzi of Trend Micro and Francesco Sortino from Celada Spa reported this vulnerability.
Affected Vendor
Haas
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.