First published: Tue Jan 14 2020(Updated: )
ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the HMI interface.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
ABB CP651 | <=bsp_un30_1.76 | |
ABB CP651 | ||
ABB CP651 | <=bsp_un30_1.76 | |
Abb Cp651-web Firmware | ||
Abb Cp661 Firmware | <=bsp_un30_1.76 | |
Abb Cp661 Firmware | ||
Abb Cp661-web Firmware | <=bsp_un30_1.76 | |
ABB CP661 | ||
Abb Cp665-web Firmware | <=bsp_un30_1.76 | |
Abb Cp665-web Firmware | ||
Abb Cp665 Firmware | <=bsp_un30_1.76 | |
Abb Cp665-web Firmware | ||
Abb Cp676 Firmware | <=bsp_un30_1.76 | |
Abb Cp676 Firmware | ||
Abb Cp676 | <=bsp_un30_1.76 | |
Abb Cp676-web |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10995 has a medium severity rating, indicating a moderate risk of exploitation.
To mitigate CVE-2019-10995, update the ABB CP651 HMI products to a version later than BSP UN30 v1.76.
CVE-2019-10995 affects ABB CP651 HMI products versions BSP UN30 v1.76 and earlier.
The primary concern of CVE-2019-10995 is that hidden administrative accounts can be exploited during the provisioning phase.
There are no official workarounds for CVE-2019-10995; the only solution is to apply the appropriate firmware update.