CVE-2022-31484
User Account Deletion Unauthenticated
An unauthenticated attacker can send a specially crafted network packet to delete a user from the web interface. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The impact of this vulnerability is that an unauthenticated attacker could restrict access to the web interface to legitimate users and potentially requiring them to use the default user dip switch procedure to gain access back.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
HID Mercury · EP4502HID Mercury · LP1501HID Mercury · LP1502HID Mercury · LP2500HID Mercury · LP4502LenelS2 · LNL-4420LenelS2 · LNL-X2210LenelS2 · LNL-X2220LenelS2 · LNL-X3300LenelS2 · LNL-X4420LenelS2 · S2-LP-1501LenelS2 · S2-LP-1502LenelS2 · S2-LP-2500LenelS2 · S2-LP-4502¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →