9.8
CVE-2022-2242
- EPSS 0.35%
- Veröffentlicht 10.08.2022 11:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:36
- Quelle info@cert.vde.com
- CVE-Watchlists
- Unerledigt
The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kuka ≫ Systemsoftware V/kss Version >= 8.2 < 8.6.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.566 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| info@cert.vde.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.