CVE-2022-25922

MEDIUM

PLC4TRUCKS Firmware - Unauthenticated Diagnostic Function Access via J2497 Message Replay

Title source: llm
STIX 2.1

Description

Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked by replaying J2497 messages. There is no authentication or authorization for these functions.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsa-22-063-01

Scores

CVSS v3 6.1
EPSS 0.0115
EPSS Percentile 62.6%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
hegemonelectronics/plc4trucks_firmware j2497
Published Mar 10, 2022
Tracked Since Feb 18, 2026