CVE-2022-2474 describes a critical authentication bypass vulnerability in Haas Controller version 100.20.000.1110, specifically within its "Ethernet Q Commands" service. This flaw allows any user on the same network segment, including remote attackers, to access the service without authentication. With a CVSS score of 8.0 (High), the vulnerability presents a significant risk, enabling unauthorized users to write malicious macros to the device, leading to potential compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the absence of authentication makes this a straightforward attack for an adversary with network access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
100.20.000.1110CPE matchmatch criteria | cpe:2.3:o:haascnc:haas_controller_firmware:100.20.000.1110:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.