CVE-2022-47557

Vulnerability in ekorCCP and ekorRCI that could allow an attacker with access to the network where the device is located to decrypt the credentials of privileged users, and subsequently gain access to the system to perform malicious actions.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ormazabal:ekorrci_firmware:601j:*:*:*:*:*:*:*
cpe:2.3:h:ormazabal:ekorrci:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:ormazabal:ekorccp_firmware:601j:*:*:*:*:*:*:*
cpe:2.3:h:ormazabal:ekorccp:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:32

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ormazabal-products - Third Party Advisory () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ormazabal-products - Third Party Advisory

07 Nov 2023, 03:56

Type Values Removed Values Added
Summary ** UNSUPPPORTED WHEN ASSIGNED ** Vulnerability in ekorCCP and ekorRCI that could allow an attacker with access to the network where the device is located to decrypt the credentials of privileged users, and subsequently gain access to the system to perform malicious actions. Vulnerability in ekorCCP and ekorRCI that could allow an attacker with access to the network where the device is located to decrypt the credentials of privileged users, and subsequently gain access to the system to perform malicious actions.

22 Sep 2023, 15:14

Type Values Removed Values Added
First Time Ormazabal ekorccp Firmware
Ormazabal ekorrci Firmware
Ormazabal ekorccp
Ormazabal
Ormazabal ekorrci
CWE CWE-916
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:o:ormazabal:ekorccp_firmware:601j:*:*:*:*:*:*:*
cpe:2.3:h:ormazabal:ekorrci:-:*:*:*:*:*:*:*
cpe:2.3:h:ormazabal:ekorccp:-:*:*:*:*:*:*:*
cpe:2.3:o:ormazabal:ekorrci_firmware:601j:*:*:*:*:*:*:*
References (MISC) https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ormazabal-products - (MISC) https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-ormazabal-products - Third Party Advisory

19 Sep 2023, 13:23

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-19 13:16

Updated : 2024-11-21 07:32


NVD link : CVE-2022-47557

Mitre link : CVE-2022-47557

CVE.ORG link : CVE-2022-47557


JSON object : View

Products Affected

ormazabal

  • ekorrci
  • ekorccp_firmware
  • ekorrci_firmware
  • ekorccp
CWE
CWE-916

Use of Password Hash With Insufficient Computational Effort