CVE Vulnerabilities

CVE-2022-2475

Published: Oct 28, 2022 | Modified: Nov 02, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the Ethernet Q Commands service. Any user is able to write macros into registers outside of the authorized accessible range. This could allow a user to access privileged resources or resources out of context.

Affected Software

Name Vendor Start Version End Version
Haas_controller_firmware Haascnc 100.20.000.1110 100.20.000.1110

References