First published: Tue Jan 03 2023(Updated: )
Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, which could allow an attacker to obtain user credentials and gain access to system data.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Prosys OPC UA Simulation Server | ||
Prosysopc Ua Modbus Server | <1.4.20 | |
Prosys OPC UA Simulation Server | <5.4.0 |
Prosys has released updates for the following products: • UA Simulation Server: Update to v5.4.0 • UA Modbus Server: Update to 1.4.20
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2967 is classified as a critical vulnerability due to its potential impact on user credential security.
To mitigate CVE-2022-2967, upgrade Prosys OPC UA Simulation Server to version 5.3.0-64 or later, and UA Modbus Server to version 1.4.20 or later.
CVE-2022-2967 affects Prosys OPC UA Simulation Server versions prior to 5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior.
An attacker with network access to the affected systems could exploit CVE-2022-2967 to obtain user credentials.
Exploitation of CVE-2022-2967 could lead to unauthorized access to system data and compromise system integrity.