CVE-2022-1524

LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit, including credentials.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-153-02 Third Party Advisory US Government Resource
Configurations

Configuration 1


Information

Published : 2022-06-24 03:15

Updated : 2022-07-01 05:32


NVD link : CVE-2022-1524

Mitre link : CVE-2022-1524

Products Affected
No products.
CWE
CWE-319

Cleartext Transmission of Sensitive Information