Vulnerabilities > CVE-2022-2641 - Use of Hard-coded Cryptographic Key vulnerability in Hornerautomation Rcc972 Firmware 15.40

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
hornerautomation
CWE-321
critical

Summary

Horner Automation’s RCC 972 with firmware version 15.40 has a static encryption key on the device. This could allow an attacker to perform unauthorized changes to the device, remotely execute arbitrary code, or cause a denial-of-service condition.

Vulnerable Configurations

Part Description Count
OS
Hornerautomation
1
Hardware
Hornerautomation
1

Common Weakness Enumeration (CWE)