CVE-2022-30320 describes a weak credential hashing scheme in Saia Burgess Controls (SBC) PCD devices, including those used with Honeywell Saia PG5 Controls Suite, affecting the S-Bus (5050/UDP) authentication. The vulnerability stems from the use of a cryptographically insecure CRC-16 based hashing algorithm for passwords, allowing an attacker to bypass authentication. With a CVSS score of 4.3 (MEDIUM), this vulnerability has an adjacent attack vector and low attack complexity, potentially leading to unauthorized access to sensitive engineering functionality like control logic manipulation. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:honeywell:saia_pg5_controls_suite:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.