CVE Vulnerabilities

CVE-2022-26131

Improper Protection against Electromagnetic Fault Injection (EM-FI)

Published: Mar 10, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals.

Weakness

The device is susceptible to electromagnetic fault injection attacks, causing device internal information to be compromised or security mechanisms to be bypassed.

Affected Software

Name Vendor Start Version End Version
Plc4trucks_firmware Hegemonelectronics j2497 (including) j2497 (including)

Extended Description

Electromagnetic fault injection may allow an attacker to locally and dynamically modify the signals (both internal and external) of an integrated circuit. EM-FI attacks consist of producing a local, transient magnetic field near the device, inducing current in the device wires. A typical EMFI setup is made up of a pulse injection circuit that generates a high current transient in an EMI coil, producing an abrupt magnetic pulse which couples to the target producing faults in the device, which can lead to:

Potential Mitigations

References