← Back

CVE-2019-7229

nvd nist
Published: Jun 24, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.3
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 6.0
Source: NVD

Description

The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.

Affected (8)

8 products
Board Support Package Un31
Cp620 Firmware
Cp620 Web Firmware
Cp630 Firmware
Cp630 Web Firmware
Cp635 Firmware
Cp635 B Firmware
Cp635 Web Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.31
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.8.0.424
Running on/withPlatform Versions
Abb
Cp620
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.8.0.424
Running on/withPlatform Versions
Abb
Cp620 Web
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.0.8.424
Running on/withPlatform Versions
Abb
Cp630
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.8.0.424
Running on/withPlatform Versions
Abb
Cp630 Web
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.8.0.424
Running on/withPlatform Versions
Abb
Cp635
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.8.0.424
Running on/withPlatform Versions
Abb
Cp635 B
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.8.0.424
Running on/withPlatform Versions
Abb
Cp635 Web
All versions

References (12)

Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.