CVE & CISA-KEV Catalog

CVE-2022-31479

CRITICALEPSS 81th pctl
9.6
CVSS v3
NVD

Description

An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable. The injected commands only get executed during start up or when unsafe calls regarding the hostname are used. This allows the attacker to gain remote access to the device and can make their persistence permanent by modifying the filesystem.

How to fix

Remediation Available
ep4502 firmwareNVD
Affected:< 1.296Fixed in:1.296CVE-2022-31479derived from NVD
lenels2 lnl-4420 firmwareNVD
Affected:< 1.296Fixed in:1.296CVE-2022-31479derived from NVD
lenels2 lnl-x2210 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lenels2 lnl-x2220 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lenels2 lnl-x3300 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lenels2 lnl-x4420 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lenels2 s2-lp-1501 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lenels2 s2-lp-1502 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lenels2 s2-lp-2500 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lenels2 s2-lp-4502 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lp1501 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lp1502 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lp2500 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD
lp4502 firmwareNVD
Affected:< 1.302Fixed in:1.302CVE-2022-31479derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeChanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Exploit Intelligence

2.32%probability of exploitation in 30 days
81stpercentile

Elevated risk: more likely to be exploited than 81% of all known CVEs.

References

Vendor Advisory1
Embed a live status badge for CVE-2022-31479
CVE-2022-31479 severity badge

Markdown

[![CVE-2022-31479](https://tridentstack.com/cve/badge/CVE-2022-31479.svg)](https://tridentstack.com/cve/CVE-2022-31479)

HTML

<a href="https://tridentstack.com/cve/CVE-2022-31479"><img src="https://tridentstack.com/cve/badge/CVE-2022-31479.svg" alt="CVE-2022-31479"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.