« Volver al listado

CVE-2022-2242

Estado: ModificadaCrítica (9.8)—

The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-2242",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "info@cert.vde.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "info@cert.vde.com",
      "affectedData": [
        {
          "vendor": "KUKA",
          "product": "SystemSoftware V/KSS",
          "versions": [
            {
              "status": "affected",
              "version": "8.2",
              "lessThan": "8.6.5",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-10T11:15:08.047",
  "references": [
    {
      "url": "https://www.kuka.com/advisories-CVE-2022-2242",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "info@cert.vde.com"
    },
    {
      "url": "https://www.kuka.com/advisories-CVE-2022-2242",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "info@cert.vde.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default)."
    },
    {
      "lang": "es",
      "value": "El KUKA SystemSoftware V/KSS en versiones anteriores a 8.6.5, es propenso a un control de acceso inapropiado, ya que un atacante no autorizado puede leer y escribir directamente las configuraciones del robot cuando el control de acceso no está disponible o no está habilitado (por defecto)"
    }
  ],
  "lastModified": "2026-06-17T04:41:33.003",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:kuka:systemsoftware_v\\/kss:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08A86D9F-4341-46E9-9F3A-492DFBAC2401",
              "versionEndExcluding": "8.6.5",
              "versionStartIncluding": "8.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "info@cert.vde.com"
}