CVE-2022-30275: High severity motorola solutions mdlc vulnerability
The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini driver configuration file. In addition, this password is used for access control to MOSCAD/STS projects protected with the Legacy Password feature. In this case, an insecure CRC of the password is present in the project file: this CRC is validated against the password in the driver configuration file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30275?
CVE-2022-30275 has a medium severity level due to the exposure of cleartext passwords.
How do I fix CVE-2022-30275?
To fix CVE-2022-30275, update the Motorola Solutions MDLC software to a newer version that enhances password protection.
What impact does CVE-2022-30275 have on my system?
CVE-2022-30275 can allow unauthorized access to sensitive communications if the cleartext password is compromised.
Which versions of the MDLC are affected by CVE-2022-30275?
CVE-2022-30275 affects Motorola Solutions MDLC versions 4.80.0024, 4.82.004, and 4.83.001.
Is CVE-2022-30275 part of any compliance regulations?
Yes, organizations using affected versions may face compliance issues due to the security flaws identified in CVE-2022-30275.