CVE-2022-31479

CRITICAL

An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts pr...

Affects 28 products across 3 vendors.

BCS8.73
CVSS 3.19.8
EPSS2.4%
Percentile83th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

CWE-693: CWE-693
Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-51 Poison Web Service Registry
via CWE-693
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-693
CAPEC-59 Session Credential Falsification through Prediction
via CWE-693
CAPEC-65 Sniff Application Code
via CWE-693
Show all 22
via CWE-78
via CWE-78
via CWE-78
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2022-31479 affects HID Mercury Intelligent Controllers, allowing an unauthenticated attacker to execute shell commands by updating the hostname with a crafted name. This can lead to remote access, monitoring, and modification of device operations, potentially causing instability. Firmware versions prior to 1.302 for LP series and 1.296 for EP series are vulnerable. The CVSS score is 9.8, indicating a critical severity level.

BSID: BS-2022-GLOBAL-068246-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2022-31479?
CVE-2022-31479 affects HID Mercury Intelligent Controllers, allowing an unauthenticated attacker to execute shell commands by updating the hostname with a crafted name. This can lead to remote access, monitoring, and modification of device operations, potentially causing instability. Firmware versions prior to 1.302 for LP series and 1.296 for EP series are vulnerable. The CVSS score is 9.8, indicating a critical severity level.
What is the CVSS score for CVE-2022-31479?
CVE-2022-31479 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 2.4%.
Is CVE-2022-31479 actively exploited?
No confirmed active exploitation of CVE-2022-31479 as of 2026-05-30.
How do I remediate CVE-2022-31479?
Priority: IMMEDIATE. Advisory: https://www.corporate.carrier.com/product-security/advisories-resources/ PSIRT: [email protected]
What systems are affected by CVE-2022-31479?
CVE-2022-31479 affects: Carrier, Carrier, Carrier, Carrier, Carrier, Carrier, Carrier, Carrier.
What NERC-CIP standard applies to CVE-2022-31479?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 by allowing an unauthenticated attacker to execute commands on the device, which can compromise the security and integrity of the control system.
What IEC 62443 requirement maps to CVE-2022-31479?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves the execution of unauthorized commands on the device, which can lead to loss of control and potential damage to the system.
Vulnerability Details
CVE IDCVE-2022-31479
BSIDBS-2022-GLOBAL-068246-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2022-06-06
Last Modified2024-11-21
ICS Relevance90%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable. The injected commands only get executed during start up or when unsafe calls regarding the hostname are used. This allows the attacker to gain remote access to the device and can make their persistence permanent by modifying the filesystem.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An unauthenticated attacker can exploit this vulnerability by sending a specially crafted hostname update request to the affected device. This request, when processed, allows the execution of shell commands during the core collection process. The commands are executed during startup or when unsafe calls regarding the hostname are made, providing the attacker with remote access and the ability to modify the filesystem, monitor communications, and change configuration files.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Carrier Lenels2 S2-Lp-4502
Carrier Lenels2 Lnl-4420 Firmware
Carrier Lenels2 Lnl-4420
Carrier Lenels2 Lnl-X2210 Firmware
Carrier Lenels2 Lnl-X2210
Carrier Lenels2 Lnl-X2220 Firmware
Carrier Lenels2 Lnl-X2220
Carrier Lenels2 Lnl-X3300 Firmware
Carrier Lenels2 Lnl-X3300
Carrier Lenels2 Lnl-X4420 Firmware
Carrier Lenels2 Lnl-X4420
Carrier Lenels2 S2-Lp-1501 Firmware
Carrier Lenels2 S2-Lp-1501
Carrier Lenels2 S2-Lp-1502 Firmware
Carrier Lenels2 S2-Lp-1502
Carrier Lenels2 S2-Lp-2500 Firmware
Carrier Lenels2 S2-Lp-2500
Carrier Lenels2 S2-Lp-4502 Firmware
Hidglobal Ep4502
Hidglobal Lp1501 Firmware
Hidglobal Lp1501
Hidglobal Lp1502 Firmware
Hidglobal Lp1502
Hidglobal Lp2500 Firmware
Hidglobal Lp2500
Hidglobal Lp4502 Firmware
Hidglobal Lp4502
Hidglobal Ep4502 Firmware
Honeywell —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 1531 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict input validation for hostname updates and restrict access to the hostname update function to only trusted users. Ensure that all network communications are encrypted and authenticated.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 by allowing an unauthenticated attacker to execute commands on the device, which can compromise the security and integrity of the control system.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves the execution of unauthorized commands on the device, which can lead to loss of control and potential damage to the system.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash5610ee03d65537cd1d9ca5afba96a758bf753ff2b2c56bfb58506f9c55a97d8bd5c271a03579da1d7880d8a0443c081a423f9bc6e5b7e83b5b5f66da37e03a19
Related CVEs affecting Carrier
CVE-2022-31481 10.0 An unauthenticated attacker can send a specially crafted update file to the d... CVE-2025-53213 9.9 Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions... CVE-2022-31486 8.8 An authenticated attacker can send a specially crafted route to the “edit_rou... CVE-2022-31483 8.8 An authenticated attacker can upload a file with a filename including “..” an... CVE-2017-9650 7.8 An Unrestricted Upload of File with Dangerous Type issue was discovered in Au...
View all Carrier CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →