CVE-2022-30269
- EPSS 0.09%
- Veröffentlicht 26.07.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 07:02:27
Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application image...
CVE-2022-30270
- EPSS 0.29%
- Veröffentlicht 26.07.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 07:02:28
The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. ...
CVE-2022-30271
- EPSS 0.19%
- Veröffentlicht 26.07.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 07:02:28
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by d...
CVE-2022-30272
- EPSS 0.1%
- Veröffentlicht 26.07.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 07:02:28
The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed throug...
CVE-2022-30274
- EPSS 0.17%
- Veröffentlicht 26.07.2022 23:15:08
- Zuletzt bearbeitet 21.11.2024 07:02:28
The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryp...