Security Advisory

CVE-2022-2474

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-10-28 17:11:30
Last updated 2025-04-16 16:07:37
Assigner icscert
State PUBLISHED

Description

Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device.