CVE-2022-2640 - CVE House
Back to Database
Status published High CVE-2022-2640

The Config-files of Horner Automation’s RCC 972 with firmware version...

Vulnerability Description

The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol (FTP) and Hypertext Transfer Protocol (HTTP).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-2640

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • m1etz reported these vulnerabilities through the Computer Emergency Response Team, CERT-Bund, to CISA

Affected Vendor

Horner Automation

View all reports →

Affected Software

Remote Compact Controller (RCC) 972
Vulnerable Versions:
Firmware Version 15.40

Timeline

Official Publish: December 12th, 2022
Last Modified: April 16th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.