CVE-2022-29519
Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an adjacent attacker to login the affected products and alter device configuration settings or tamper with…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.38%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 to R4.31, which may allow an adjacent attacker to login the affected products and alter device configuration settings or tamper with device firmware.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- yokogawa/stardom fcj firmware · yokogawa/stardom fcn firmware
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/vu/JVNVU95452299/index.htmlMitigation, Third Party Advisory, VDB Entry
- https://web-material3.yokogawa.com/1/32885/files/YSAR-22-0007-E.pdfMitigation, Vendor Advisory
- https://web-material3.yokogawa.com/19/32885/files/YSAR-22-0007-J.pdfMitigation, Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-01Mitigation, Third Party Advisory, US Government Resource
- https://jvn.jp/vu/JVNVU95452299/index.htmlMitigation, Third Party Advisory, VDB Entry
- https://web-material3.yokogawa.com/1/32885/files/YSAR-22-0007-E.pdfMitigation, Vendor Advisory
- https://web-material3.yokogawa.com/19/32885/files/YSAR-22-0007-J.pdfMitigation, Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-01Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.