CVE-2022-25359 is a critical vulnerability affecting ICL ScadaFlex II SCADA Controllers SC-1 and SC-2 (version 1.03.07), allowing unauthenticated remote attackers to overwrite, delete, or create files. With a CVSS score of 9.1 (CRITICAL) and a FAUCET Risk Score of 98/100, this vulnerability has a low attack complexity and can lead to high integrity and availability impacts. While not on CISA's KEV catalog, public exploit code is available via ExploitDB, and it has garnered significant community discussion and media coverage, including a CISA warning.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.01.01CPE matchmatch criteria | cpe:2.3:o:iclinks:scadaflex_ii_firmware:1.01.01:*:*:*:*:*:*:* | ||
1.01.14CPE matchmatch criteria | cpe:2.3:o:iclinks:scadaflex_ii_firmware:1.01.14:*:*:*:*:*:*:* | ||
1.02.01CPE matchmatch criteria | cpe:2.3:o:iclinks:scadaflex_ii_firmware:1.02.01:*:*:*:*:*:*:* | ||
1.02.15CPE matchmatch criteria | cpe:2.3:o:iclinks:scadaflex_ii_firmware:1.02.15:*:*:*:*:*:*:* | ||
1.02.20CPE matchmatch criteria | cpe:2.3:o:iclinks:scadaflex_ii_firmware:1.02.20:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.