SB2022060318 - Multiple vulnerabilities in Carrier LenelS2 HID Mercury access panels



SB2022060318 - Multiple vulnerabilities in Carrier LenelS2 HID Mercury access panels

Published: June 3, 2022

Security Bulletin ID SB2022060318
Severity
High
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 67% Medium 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Protection Mechanism Failure (CVE-ID: CVE-2022-31479)

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures. A remote attacker can update the hostname with a specially crafted name and execute arbitrary shell command during the core collection process.


2) Direct Request ('Forced Browsing') (CVE-ID: CVE-2022-31480)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the affected application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files. A remote attacker can upload arbitrary firmware files to the target device and cause a denial of service condition on the system.


3) Buffer overflow (CVE-ID: CVE-2022-31481)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote attacker can send a specially crafted update file, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install update from vendor's website.