← back
CVE-2022-31801criticalCWE-345

Insufficient Verification of Data Vulnerability in ProConOS/ProConOS eCLR SDK and MULTIPROG Engineering tool

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
In short

An attacker can remotely upload harmful code to devices running ProConOS without needing a password, taking complete control of the device. This is critical because these devices often control important industrial systems.

Technical detail

The vulnerability allows unauthenticated remote code upload to ProConOS/eCLR-based devices due to insufficient data verification (CWE-345). An attacker can exploit this over the network to execute arbitrary logic and achieve full device compromise without prior authentication or authorization.

Summary generated and translated by AI from the official description.
An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H