CVE-2022-2242

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
10/08/2022
Last modified:
12/08/2022

Description

The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kuka:systemsoftware_v\/kss:*:*:*:*:*:*:*:* 8.2 (including) 8.6.5 (excluding)


References to Advisories, Solutions, and Tools