First published: Thu Dec 01 2022(Updated: )
Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an attacker to perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service condition.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Hornerautomation Rcc972 Firmware | =15.40 | |
Hornerautomation Rcc972 | ||
Horner Automation RCC 972: Firmware Version 15.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2641 is a vulnerability in Horner Automation’s RCC 972 with firmware version 15.40 that has a static encryption key on the device.
An attacker could perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service condition.
CVE-2022-2641 is considered critical with a severity score of 9.8
To fix CVE-2022-2641, it is recommended to update the firmware version of Horner Automation’s RCC 972 to a version that addresses the vulnerability.
You can find more information about CVE-2022-2641 in the advisory published by the Cybersecurity and Infrastructure Security Agency (CISA) at https://www.cisa.gov/uscert/ics/advisories/icsa-22-335-02