CVE-2022-25359
CRITICALICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 - Unauthenticated Arbitrary File Write
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2022-25359. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates unauthenticated file write/overwrite and delete operations on ICL ScadaFlex II SCADA Controllers via crafted HTTP requests. It leverages a vulnerability in the device's web interface to perform CRUD operations on arbitrary files.
Description
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, delete, or create files.
Exploits (1)
This exploit demonstrates unauthenticated file write/overwrite and delete operations on ICL ScadaFlex II SCADA Controllers via crafted HTTP requests. It leverages a vulnerability in the device's web interface to perform CRUD operations on arbitrary files.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H