CVE-2019-7229
8.3
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 6.0
Source: NVD
Description
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.31 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.0.424 |
| Running on/with | Platform Versions |
|---|---|
Abb Cp620 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.0.424 |
| Running on/with | Platform Versions |
|---|---|
Abb Cp620 Web | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.8.424 |
| Running on/with | Platform Versions |
|---|---|
Abb Cp630 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.0.424 |
| Running on/with | Platform Versions |
|---|---|
Abb Cp630 Web | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.0.424 |
| Running on/with | Platform Versions |
|---|---|
Abb Cp635 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.0.424 |
| Running on/with | Platform Versions |
|---|---|
Abb Cp635 B | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.0.424 |
| Running on/with | Platform Versions |
|---|---|
Abb Cp635 Web | All versions |
References (12)
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
MitigationPatchVendor Advisory
Source: cve@mitre.org
MitigationPatchVendor Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.