Successful exploitation of this vulnerability, discovered by Alpha Strike Labs by Limes Security, could allow an attacker to open control cabinets secured with Rittal locks.
Rittal reports this vulnerability affects the following control cabinet locks: CMC III.
In the vulnerability, a malicious actor can clone access cards used to open control cabinets secured with Rittal CMC III locks.
CVE-2022-40633 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 4.8.
The product sees use in the commercial facilities, communications, critical manufacturing, energy, and information technology sectors. It also sees action on a global basis.
No known public exploits specifically target this vulnerability. This vulnerability is not exploitable remotely. However, an attacker with low skill level could leverage the vulnerability.
Germany-based Rittal said the CMC III and the CMC compact products are at end-of-life and no longer supported; security gaps will be addressed in their next generation product.
Rittal plans to notify all known users of the issue. They recommend a PIN pad be added for a two-step authentication process. Users should contact Rittal support for further information.

