CVE-2022-2967: High severity prosys opc ua simulation server vulnerability
Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, which could allow an attacker to obtain user credentials and gain access to system data.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2967?
CVE-2022-2967 is classified as a critical vulnerability due to its potential impact on user credential security.
How do I fix CVE-2022-2967?
To mitigate CVE-2022-2967, upgrade Prosys OPC UA Simulation Server to version 5.3.0-64 or later, and UA Modbus Server to version 1.4.20 or later.
What systems are affected by CVE-2022-2967?
CVE-2022-2967 affects Prosys OPC UA Simulation Server versions prior to 5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior.
What type of attacker can exploit CVE-2022-2967?
An attacker with network access to the affected systems could exploit CVE-2022-2967 to obtain user credentials.
What are the consequences of CVE-2022-2967?
Exploitation of CVE-2022-2967 could lead to unauthorized access to system data and compromise system integrity.