VulnerabilityModified
CVE-2022-25359
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
CRITICAL 9.1EPSS 37.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 37.3%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 37.30% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- iclinks/scadaflex ii firmware · iclinks/weblib
- Source
- cve@mitre.org
References
- http://files.iclinks.com/datasheets/Scadaflex%20II/Scadaflex%20SC-1%20&%20SC-2_A1_compressed.pdfProduct, Vendor Advisory
- https://packetstormsecurity.com/files/166103/ICL-ScadaFlex-II-SCADA-Controllers-SC-1-SC-2-1.03.07-Remote-File-Modification.htmlExploit, Third Party Advisory, VDB Entry
- http://files.iclinks.com/datasheets/Scadaflex%20II/Scadaflex%20SC-1%20&%20SC-2_A1_compressed.pdfProduct, Vendor Advisory
- https://packetstormsecurity.com/files/166103/ICL-ScadaFlex-II-SCADA-Controllers-SC-1-SC-2-1.03.07-Remote-File-Modification.htmlExploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.