← Back to browse · API

CVE-2022-31481

Severity
CRITICAL
CVSS
10.0
EPSS
0.015
Risk score
40.52
CISA KEV
No
PoC
No
Published
2022-06-06
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2022-52941, GHSA-4WGJ-2885-VW22
Products
HID Mercury:EP4502 ALL <1.296, HID Mercury:LP1501 ALL <1.302, HID Mercury:LP1502 ALL <1.302, HID Mercury:LP2500 ALL <1.302, HID Mercury:LP4502 ALL <1.302, LenelS2:LNL-4420 ALL <1.296, LenelS2:LNL-X2210 ALL <1.302, LenelS2:LNL-X2220 ALL <1.302, LenelS2:LNL-X3300 ALL <1.302, LenelS2:LNL-X4420 ALL <1.302, LenelS2:S2-LP-1501 ALL <1.302, LenelS2:S2-LP-1502 ALL <1.302, LenelS2:S2-LP-2500 ALL <1.302, LenelS2:S2-LP-4502 ALL <1.302
Sources
euvd EUVD-2022-52941

Description

An unauthenticated attacker can send a specially crafted update file to the device that can overflow a buffer. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. The overflowed data can allow the attacker to manipulate the “normal” code execution to that of their choosing. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable.

References