CVE-2022-2640

The Config-files of Horner Automation’s RCC 972 with firmware version 15.40 are encrypted with weak XOR encryption vulnerable to reverse engineering. This could allow an attacker to obtain credentials to run services such as File Transfer Protocol (FTP) and Hypertext Transfer Protocol (HTTP).
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-335-02 Patch Third Party Advisory
Configurations

Configuration 1


Information

Published : 2022-12-02 08:15

Updated : 2022-12-06 12:32


NVD link : CVE-2022-2640

Mitre link : CVE-2022-2640

Products Affected
No products.
CWE
CWE-326

Inadequate Encryption Strength