First published: Tue Feb 01 2022(Updated: )
The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to achieve Web Server login and perform further actions.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Advantech Adam-3600 Firmware | <=2.6.2 | |
Advantech Adam-3600 | ||
Advantech ADAM-3600: Version 2.6.2 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22987 is a vulnerability in the Advantech Adam-3600 Firmware, where a hardcoded private key is available inside the project folder.
CVE-2022-22987 has a severity rating of 9.8 (critical).
CVE-2022-22987 may allow an attacker to achieve Web Server login and perform further actions.
Versions up to and inclusive of 2.6.2 of the Advantech Adam-3600 Firmware are affected by CVE-2022-22987.
No, the Advantech Adam-3600 device itself is not vulnerable to CVE-2022-22987.
To mitigate the vulnerability, it is recommended to update the Advantech Adam-3600 Firmware to a version higher than 2.6.2.
CWE-798 is a classification for incorrect default permissions, which may be relevant to the hardcoded private key vulnerability in Advantech Adam-3600 Firmware.
CWE-321 is a classification for Use of Hard-coded Cryptographic Key, which is relevant to the hardcoded private key vulnerability in Advantech Adam-3600 Firmware.
You can find more information about CVE-2022-22987 on the CISA website at https://www.cisa.gov/uscert/ics/advisories/icsa-22-032-02.