CVE Database
/

CVE-2022-32514

Back to search

CVE-2022-32514

Published: Jan 30, 2023

Modified: Feb 5, 2025

PUBLISHED

CVSS v3.1

9.8

CRITICAL

Description

A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to gain control of the device when logging into a web page. Affected Products: C-Bus Network Automation Controller - LSS5500NAC (Versions prior to V1.10.0), Wiser for C-Bus Automation Controller - LSS5500SHAC (Versions prior to V1.10.0), Clipsal C-Bus Network Automation Controller - 5500NAC (Versions prior to V1.10.0), Clipsal Wiser for C-Bus Automation Controller - 5500SHAC (Versions prior to V1.10.0), SpaceLogic C-Bus Network Automation Controller - 5500NAC2 (Versions prior to V1.10.0), SpaceLogic C-Bus Application Controller - 5500AC2 (Versions prior to V1.10.0)

VendorProductVersions

Schneider Electric

C-Bus Network Automation Controller, LSS5500NAC

affected
All - < V1.10.0

Schneider Electric

Wiser for C-Bus Automation Controller, LSS5500SHAC

affected
All - < V1.10.0

Schneider Electric

Clipsal C-Bus Network Automation Controller, 5500NAC

affected
All - < V1.10.0

Schneider Electric

Clipsal Wiser for C-Bus Automation Controller, 5500SHAC

affected
All - < V1.10.0

Schneider Electric

SpaceLogic C-Bus Network Automation Controller, 5500NAC2

affected
All - < V1.10.0

Schneider Electric

SpaceLogic C-Bus Application Controller, 5500AC2

affected
All - < V1.10.0

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now