CVE-2023-22807

CRITICAL

LS ELECTRIC XBC-DN32U Firmware 01.80 - Improper Access Control via XGT Protocol

Title source: llm
STIX 2.1

Description

LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-23-040-02

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 47.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
ls-electric/xbc-dn32u_firmware 01.80
Published Feb 15, 2023
Tracked Since Feb 18, 2026