9.1

CVE-2022-29951

JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and changing configuration settings. This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JtektPc10g-cpu Tcc-6353 Firmware Version-
   JtektPc10g-cpu Tcc-6353 Version-
JtektPc10ge Tcc-6464 Firmware Version-
   JtektPc10ge Tcc-6464 Version-
JtektPc10p Tcc-6372 Firmware Version-
   JtektPc10p Tcc-6372 Version-
JtektPc10p-dp Tcc-6726 Firmware Version-
   JtektPc10p-dp Tcc-6726 Version-
JtektPc10b-p Tcc-6373 Firmware Version-
   JtektPc10b-p Tcc-6373 Version-
JtektPc10b Tcc-1021 Firmware Version-
   JtektPc10b Tcc-1021 Version-
JtektPc10e Tcc-4737 Firmware Version-
   JtektPc10e Tcc-4737 Version-
JtektPc10el Tcc-4747 Firmware Version-
   JtektPc10el Tcc-4747 Version-
JtektPlus Cpu Tcc-6740 Firmware Version-
   JtektPlus Cpu Tcc-6740 Version-
JtektPc3jx Tcc-6901 Firmware Version-
   JtektPc3jx Tcc-6901 Version-
JtektPc3jx-d Tcc-6902 Firmware Version-
   JtektPc3jx-d Tcc-6902 Version-
JtektPc10pe Tcc-1101 Firmware Version-
   JtektPc10pe Tcc-1101 Version-
JtektPcdl Tkc-6688 Firmware Version-
   JtektPcdl Tkc-6688 Version-
JtektNano 10gx Tuc-1157 Firmware Version-
   JtektNano 10gx Tuc-1157 Version-
JtektNano Cpu Tuc-6941 Firmware Version-
   JtektNano Cpu Tuc-6941 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.563
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.