ZeroHour

CVE-2022-2474

CVSS 3.1
8.0 high
EPSS
<1%p52
Published
()
Modified
Description

Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device.

Vendors
haascnc
Products
haas controller firmware
Weakness
CWE-306
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.