CVE-2022-2474

Publication date

2022-10-28 17:11:30

Family

icscert

State

PUBLISHED

Description

Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the “Ethernet Q Commands” service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device.