CVE-2022-4333 - CVE House
Back to Database
Status published Critical CVE-2022-4333

Sprecher: Sprecon maintenance access with hardcoded credentials

Vulnerability Description

Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-4333

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Sprecher Automation

View all reports →

Affected Software

SPRECON-E CPU PU243x, SPRECON-E CPU PU244x, SPRECON-E CPU MC33/34, SPRECON-E CPU SPRECON-EDIR
Vulnerable Versions:
all

Timeline

Official Publish: June 1st, 2023
Last Modified: January 10th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)