CVE-2022-30271: Critical severity motorola ace1000 vulnerability
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshdservice) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-30271?
CVE-2022-30271 is a vulnerability found in the Motorola ACE1000 RTU firmware where a hardcoded SSH private key is shipped with the device, which can be used by default.
How does CVE-2022-30271 affect the Motorola ACE1000 RTU?
CVE-2022-30271 affects the Motorola ACE1000 RTU by exposing a hardcoded SSH private key, which can lead to unauthorized access to the device.
What is the severity of CVE-2022-30271?
CVE-2022-30271 has a severity rating of 9.8 (Critical).
How can I fix CVE-2022-30271 vulnerability?
To fix CVE-2022-30271 vulnerability, users should update the Motorola ACE1000 RTU firmware to a version that does not include the hardcoded SSH private key.
Where can I find more information about CVE-2022-30271?
You can find more information about CVE-2022-30271 on the official CISA website and the Forescout blog.