ZeroHour

CVE-2022-4333

CVSS 3.1
9.8 critical
EPSS
<1%p56
Published
()
Modified
Description

Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.

Vendors
sprecher-automation
Products
sprecon-e-p dq6-1 firmware, sprecon-e-p dl6-1 firmware, sprecon-e-p ds6-0 firmware, sprecon-e-c firmware, sprecon-e-t3 firmware, sprecon-e-tc ax-3110 firmware, sprecon-e ap-2200 firmware, sprecon-e cp-2131 firmware, sprecon-e cp-2330 firmware
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.