CVE-2022-31482
An unauthenticated attacker can send a specially crafted unauthenticated HTTP request to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.29. The overflowed data leads to segmentation fault and ultimately a denial-of-service condition, causing the device to reboot. The impact of this vulnerability is that an unauthenticated attacker could leverage this flaw to cause the target device to become unresponsive. An attacker could automate this attack to achieve persistent DoS, effectively rendering the target controller useless.
Published:Jun 6, 2022
Last Modified:Nov 21, 2024
EPS:Jun 6, 2022
EPSS Score:0.00645
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Carrier
Product
Lenels2 Lnl-4420
Carrier
Lenels2 Lnl-4420
Vendor
Carrier
Product
Lenels2 Lnl-4420 Firmware
Carrier
Lenels2 Lnl-4420 Firmware
Vendor
Carrier
Product
Lenels2 Lnl-x2210
Carrier
Lenels2 Lnl-x2210
Vendor
Carrier
Product
Lenels2 Lnl-x2210 Firmware
Carrier
Lenels2 Lnl-x2210 Firmware
Vendor
Carrier
Product
Lenels2 Lnl-x2220
Carrier
Lenels2 Lnl-x2220
Vendor
Carrier
Product
Lenels2 Lnl-x2220 Firmware
Carrier
Lenels2 Lnl-x2220 Firmware
Vendor
Carrier
Product
Lenels2 Lnl-x3300
Carrier
Lenels2 Lnl-x3300
Vendor
Carrier
Product
Lenels2 Lnl-x3300 Firmware
Carrier
Lenels2 Lnl-x3300 Firmware
Vendor
Carrier
Product
Lenels2 Lnl-x4420
Carrier
Lenels2 Lnl-x4420
Vendor
Carrier
Product
Lenels2 Lnl-x4420 Firmware
Carrier
Lenels2 Lnl-x4420 Firmware
Vendor
Carrier
Product
Lenels2 S2-lp-1501
Carrier
Lenels2 S2-lp-1501
Vendor
Carrier
Product
Lenels2 S2-lp-1501 Firmware
Carrier
Lenels2 S2-lp-1501 Firmware
Vendor
Carrier
Product
Lenels2 S2-lp-1502
Carrier
Lenels2 S2-lp-1502
Vendor
Carrier
Product
Lenels2 S2-lp-1502 Firmware
Carrier
Lenels2 S2-lp-1502 Firmware
Vendor
Carrier
Product
Lenels2 S2-lp-2500
Carrier
Lenels2 S2-lp-2500
Vendor
Carrier
Product
Lenels2 S2-lp-2500 Firmware
Carrier
Lenels2 S2-lp-2500 Firmware
Vendor
Carrier
Product
Lenels2 S2-lp-4502
Carrier
Lenels2 S2-lp-4502
Vendor
Carrier
Product
Lenels2 S2-lp-4502 Firmware
Carrier
Lenels2 S2-lp-4502 Firmware
Vendor
Hidglobal
Product
Ep4502
Hidglobal
Ep4502
Vendor
Hidglobal
Product
Ep4502 Firmware
Hidglobal
Ep4502 Firmware
Vendor
Hidglobal
Product
Lp1501
Hidglobal
Lp1501
Vendor
Hidglobal
Product
Lp1501 Firmware
Hidglobal
Lp1501 Firmware
Vendor
Hidglobal
Product
Lp1502
Hidglobal
Lp1502
Vendor
Hidglobal
Product
Lp1502 Firmware
Hidglobal
Lp1502 Firmware
Vendor
Hidglobal
Product
Lp2500
Hidglobal
Lp2500
Vendor
Hidglobal
Product
Lp2500 Firmware
Hidglobal
Lp2500 Firmware
Vendor
Hidglobal
Product
Lp4502
Hidglobal
Lp4502
Vendor
Hidglobal
Product
Lp4502 Firmware
Hidglobal
Lp4502 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
