CVE-2022-45914

CVSS V2 None CVSS V3 None
Description
The ESL (Electronic Shelf Label) protocol, as implemented by (for example) the OV80e934802 RF transceiver on the ETAG-2130-V4.3 20190629 board, does not use authentication, which allows attackers to change label values via 433 MHz RF signals, as demonstrated by disrupting the organization of a hospital storage unit, or changing retail pricing.
Overview
  • CVE ID
  • CVE-2022-45914
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2022-11-27T01:15:10
  • Last Modified Date
  • 2023-02-17T03:31:39
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:electronic_shelf_label_protocol_project:electronic_shelf_label_protocol:-:*:*:*:*:*:*:* 1 OR
History
Created Old Value New Value Data Type Notes
2022-11-27 02:00:30 Added to TrackCVE
2022-12-07 18:05:11 2022-11-27T01:15Z 2022-11-27T01:15:10 CVE Published Date updated
2022-12-07 18:05:11 2022-12-01T18:23:42 CVE Modified Date updated
2022-12-07 18:05:11 Analyzed Vulnerability Status updated
2022-12-07 18:05:12 CWE-862 Weakness Enumeration new
2022-12-07 18:05:13 CPE Information updated
2022-12-09 05:27:25 2022-12-09T05:15:12 CVE Modified Date updated
2022-12-09 05:27:25 Analyzed Modified Vulnerability Status updated
2022-12-09 05:27:26 References updated
2022-12-09 18:21:56 2022-12-09T17:15:11 CVE Modified Date updated
2022-12-09 18:21:57 References updated
2022-12-12 18:17:26 Modified Undergoing Analysis Vulnerability Status updated
2023-02-17 04:12:57 2023-02-17T03:31:39 CVE Modified Date updated
2023-02-17 04:12:57 Undergoing Analysis Analyzed Vulnerability Status updated
2023-02-17 04:12:58 Weakness Enumeration update