Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E prior to V3.20, all versions of XGR-CPUH prior to V1.80, all versions of XGB-XBMS prior to V3.00, all versions of XGB-XBCH prior to V1.90, and all versions of XGB-XECH prior to V1.30. This would allow an attacker to identify and decrypt the password of the affected PLCs by sniffing the PLC’s communication traffic.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-02 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2022-08-16T00:00:00

Updated: 2022-11-14T00:00:00

Reserved: 2022-08-10T00:00:00


Link: CVE-2022-2758

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-08-31T16:15:11.383

Modified: 2022-11-14T22:15:10.280


Link: CVE-2022-2758

JSON object: View

cve-icon Redhat Information

No data.

CWE