Back to overview

CVE-2022-31481

CRITICAL
10.0
CVSS 3.1
Description
An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The overflowed data can allow the attacker to manipulate the “normal” code execution to that of their choosing. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable.

Metadata

CVE ID
CVE-2022-31481
State
PUBLISHED
Assigner
Carrier
Reserved
2022-05-23 00:00 UTC
Published
2022-06-06 16:38 UTC
Last updated
2024-09-16 16:12 UTC
Primary CWE
CWE-120
CWE-120 Buffer Overflow
Vendor / Product
LenelS2 / LNL-X2210
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (14)
VendorProductPlatformVersions
HID Mercury EP4502 ALL < 1.296
HID Mercury LP1501 ALL < 1.302
HID Mercury LP1502 ALL < 1.302
HID Mercury LP2500 ALL < 1.302
HID Mercury LP4502 ALL < 1.302
LenelS2 LNL-4420 ALL < 1.296
LenelS2 LNL-X2210 ALL < 1.302
LenelS2 LNL-X2220 ALL < 1.302
LenelS2 LNL-X3300 ALL < 1.302
LenelS2 LNL-X4420 ALL < 1.302
LenelS2 S2-LP-1501 ALL < 1.302
LenelS2 S2-LP-1502 ALL < 1.302
LenelS2 S2-LP-2500 ALL < 1.302
LenelS2 S2-LP-4502 ALL < 1.302
Weakness (CWE)
CWESourceDescription
CWE-120 cna CWE-120 Buffer Overflow
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview