Vulnerability Description
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iclinks | Scadaflex Ii Firmware | 1.01.01 |
| Iclinks | Weblib | 1.13 |
| Iclinks | Scadaflex Ii | - |
Related Weaknesses (CWE)
References
- http://files.iclinks.com/datasheets/Scadaflex%20II/Scadaflex%20SC-1%20&%20SC-2_AProductVendor Advisory
- https://packetstormsecurity.com/files/166103/ICL-ScadaFlex-II-SCADA-Controllers-ExploitThird Party AdvisoryVDB Entry
- http://files.iclinks.com/datasheets/Scadaflex%20II/Scadaflex%20SC-1%20&%20SC-2_AProductVendor Advisory
- https://packetstormsecurity.com/files/166103/ICL-ScadaFlex-II-SCADA-Controllers-ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2022-25359?
CVE-2022-25359 is a vulnerability with a CVSS score of 9.1 (CRITICAL). On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
How severe is CVE-2022-25359?
CVE-2022-25359 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-25359?
Check the references section above for vendor advisories and patch information. Affected products include: Iclinks Scadaflex Ii Firmware, Iclinks Weblib, Iclinks Scadaflex Ii.