CVE-2022-2474
28.10.2022, 18:15
Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the Ethernet Q Commands service, which allows any user on the same network segment as the controller (even while connected remotely) to access the service and write unauthorized macros to the device.Enginsight
Vendor | Product | Version |
---|---|---|
haascnc | haas_controller_firmware | 100.20.000.1110 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration