CVE-2022-1596
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.
Affected (3)
Products: Abb: Rex640 Pcl1 Firmware, Rex640 Pcl2 Firmware, Rex640 Pcl3 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.0.7 |
| Running on/with | Platform Versions |
|---|---|
Abb Rex640 Pcl1 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.1.4 |
| Running on/with | Platform Versions |
|---|---|
Abb Rex640 Pcl2 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.2.1 |
| Running on/with | Platform Versions |
|---|---|
Abb Rex640 Pcl3 | All versions |
References (2)
Source: cybersecurity@ch.abb.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.