CVE-2022-31479
An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts pr...
Affects 28 products across 3 vendors.
Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.
Show all 22
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2022-31479 affects HID Mercury Intelligent Controllers, allowing an unauthenticated attacker to execute shell commands by updating the hostname with a crafted name. This can lead to remote access, monitoring, and modification of device operations, potentially causing instability. Firmware versions prior to 1.302 for LP series and 1.296 for EP series are vulnerable. The CVSS score is 9.8, indicating a critical severity level.
BSID: BS-2022-GLOBAL-068246-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2022-31479?
What is the CVSS score for CVE-2022-31479?
Is CVE-2022-31479 actively exploited?
How do I remediate CVE-2022-31479?
What systems are affected by CVE-2022-31479?
What NERC-CIP standard applies to CVE-2022-31479?
What IEC 62443 requirement maps to CVE-2022-31479?
| CVE ID | CVE-2022-31479 |
|---|---|
| BSID | BS-2022-GLOBAL-068246-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2022-06-06 |
| Last Modified | 2024-11-21 |
| ICS Relevance | 90% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable. The injected commands only get executed during start up or when unsafe calls regarding the hostname are used. This allows the attacker to gain remote access to the device and can make their persistence permanent by modifying the filesystem.
Source: NIST NVD / MITRE CVE Database
An unauthenticated attacker can exploit this vulnerability by sending a specially crafted hostname update request to the affected device. This request, when processed, allows the execution of shell commands during the core collection process. The commands are executed during startup or when unsafe calls regarding the hostname are made, providing the attacker with remote access and the ability to modify the filesystem, monitor communications, and change configuration files.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Carrier | Lenels2 S2-Lp-4502 | — |
| Carrier | Lenels2 Lnl-4420 Firmware | — |
| Carrier | Lenels2 Lnl-4420 | — |
| Carrier | Lenels2 Lnl-X2210 Firmware | — |
| Carrier | Lenels2 Lnl-X2210 | — |
| Carrier | Lenels2 Lnl-X2220 Firmware | — |
| Carrier | Lenels2 Lnl-X2220 | — |
| Carrier | Lenels2 Lnl-X3300 Firmware | — |
| Carrier | Lenels2 Lnl-X3300 | — |
| Carrier | Lenels2 Lnl-X4420 Firmware | — |
| Carrier | Lenels2 Lnl-X4420 | — |
| Carrier | Lenels2 S2-Lp-1501 Firmware | — |
| Carrier | Lenels2 S2-Lp-1501 | — |
| Carrier | Lenels2 S2-Lp-1502 Firmware | — |
| Carrier | Lenels2 S2-Lp-1502 | — |
| Carrier | Lenels2 S2-Lp-2500 Firmware | — |
| Carrier | Lenels2 S2-Lp-2500 | — |
| Carrier | Lenels2 S2-Lp-4502 Firmware | — |
| Hidglobal | Ep4502 | — |
| Hidglobal | Lp1501 Firmware | — |
| Hidglobal | Lp1501 | — |
| Hidglobal | Lp1502 Firmware | — |
| Hidglobal | Lp1502 | — |
| Hidglobal | Lp2500 Firmware | — |
| Hidglobal | Lp2500 | — |
| Hidglobal | Lp4502 Firmware | — |
| Hidglobal | Lp4502 | — |
| Hidglobal | Ep4502 Firmware | — |
| Honeywell | — | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict input validation for hostname updates and restrict access to the hostname update function to only trusted users. Ensure that all network communications are encrypted and authenticated.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 by allowing an unauthenticated attacker to execute commands on the device, which can compromise the security and integrity of the control system.
This CVE maps to SR 7.6 because it involves the execution of unauthorized commands on the device, which can lead to loss of control and potential damage to the system.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 5610ee03d65537cd1d9ca5afba96a758bf753ff2b2c56bfb58506f9c55a97d8bd5c271a03579da1d7880d8a0443c081a423f9bc6e5b7e83b5b5f66da37e03a19 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →