CVE-2019-7225: High severity abb cp620-web firmware vulnerability
The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. These credentials are the idal123 password for the IdalMaster account, and the exor password for the exor account. These credentials are used over both HTTP(S) and FTP. There is no option to disable or change these undocumented credentials. An attacker can use these credentials to login to ABB HMI to read/write HMI configuration files and also to reset the device. This affects ABB CP635 HMI, CP600 HMIClient, Panel Builder 600, IDAL FTP server, IDAL HTTP server, and multiple other HMI components.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7225?
CVE-2019-7225 has a critical severity rating due to the presence of hardcoded administrative credentials that could allow unauthorized access to sensitive functions.
How do I fix CVE-2019-7225?
To fix CVE-2019-7225, you should update all affected ABB HMI firmware to a version that does not use hardcoded credentials.
Which ABB products are affected by CVE-2019-7225?
CVE-2019-7225 affects several ABB HMI components, including certain versions of CP620, CP630, CP635, PB610, and their web firmware variants.
What are the risks associated with CVE-2019-7225?
The risks of CVE-2019-7225 include potential unauthorized access and control over the HMI systems due to the use of hardcoded credentials.
Can I still use my ABB devices if they are affected by CVE-2019-7225?
If your ABB devices are affected by CVE-2019-7225, you should implement immediate remediation steps to mitigate the risk while using them.