ZeroHour

CVE-2022-46142

CVSS 4.0
5.2 medium
EPSS
<1%p18
Published
()
Modified
Description

Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.

Vendors
siemens
Products
ruggedcom rm1224 lte\(4g\) eu firmware, ruggedcom rm1224 lte\(4g\) nam firmware, scalance m804pb firmware, scalance m812-1 adsl-router firmware, scalance m816-1 adsl-router firmware, scalance m826-2 shdsl-router firmware, scalance m874-2 firmware, scalance m874-3 firmware, scalance m876-3 firmware, scalance m876-4 firmware, scalance mum853-1 firmware, scalance mum856-1 firmware
Weakness
CWE-257, CWE-522
Vector
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.