Modbus Vulnerabilities in Innomic Products
CVE-2022-50979

6.5MEDIUM

What is CVE-2022-50979?

An unauthenticated adjacent attacker may exploit vulnerabilities in Innomic products utilizing Modbus (RS485) to manipulate configuration presets. This manipulation could lead to significant operational disruptions, underscoring the importance of securing device configurations against unauthorized access.

Affected Version(s)

AvibiaLine AVLX1 HD 5.0 2.1.1340 <= 2.1.1387

AvibiaLine AVLX1 HD 5.0 2.1.1866

AvibiaLine AVLX2 HD 5.0 2.1.1340 <= 2.1.1387

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.