CVE-2022-32513

A CWE-521: Weak Password Requirements vulnerability exists that could allow an attacker to gain control of the device when the attacker brute forces the password. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-Bus Automation Controller - LSS5500SHAC (Versions prior to V1.10.0), Clipsal C-Bus Network Automation Controller - 5500NAC (Versions prior to V1.10.0), Clipsal Wiser for C-Bus Automation Controller - 5500SHAC (Versions prior to V1.10.0), SpaceLogic C-Bus Network Automation Controller - 5500NAC2 (Versions prior to V1.10.0), SpaceLogic C-Bus Application Controller - 5500AC2 (Versions prior to V1.10.0)
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:5500ac2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:5500ac2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:5500nac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:5500nac:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:5500nac2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:5500nac2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:schneider-electric:5500shac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:5500shac:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:schneider-electric:lss5500nac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:lss5500nac:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:schneider-electric:lss5500shac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:lss5500shac:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:06

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad CWE-521: Requisitos de contraseña débiles que podría permitir a un atacante obtener el control del dispositivo cuando fuerza bruta la contraseña. Productos afectados: Controlador de automatización de red C-Bus - LSS5500NAC (versiones anteriores a V1.10.0), Wiser para controlador de automatización de red C-Bus - LSS5500SHAC (versiones anteriores a V1.10.0), Controlador de automatización de red Clipsal C-Bus - 5500NAC (versiones anteriores a V1.10.0), Clipsal Wiser para controlador de automatización C-Bus - 5500SHAC (versiones anteriores a V1.10.0), controlador de automatización de red SpaceLogic C-Bus - 5500NAC2 (versiones anteriores a V1.10.0), controlador de aplicaciones SpaceLogic C-Bus - 5500AC2 (Versiones anteriores a V1.10.0)
References () https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-06_C-Bus_Home_Automation_Products_Security_Notification.pdf - Patch, Vendor Advisory () https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-06_C-Bus_Home_Automation_Products_Security_Notification.pdf - Patch, Vendor Advisory

Information

Published : 2023-01-30 23:15

Updated : 2024-11-21 07:06


NVD link : CVE-2022-32513

Mitre link : CVE-2022-32513

CVE.ORG link : CVE-2022-32513


JSON object : View

Products Affected

schneider-electric

  • 5500shac_firmware
  • lss5500shac_firmware
  • 5500nac
  • lss5500nac
  • 5500nac_firmware
  • 5500nac2
  • lss5500nac_firmware
  • 5500nac2_firmware
  • lss5500shac
  • 5500shac
  • 5500ac2
  • 5500ac2_firmware
CWE
CWE-521

Weak Password Requirements