CVE-2021-22278: Certificate verification vulnerability in Update Manager of PCM600 Engineering Tool
A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-22278?
CVE-2021-22278 is a certificate validation vulnerability in PCM600 Update Manager that allows an attacker to install unwanted software packages on a computer with PCM600 installed.
Which software versions are affected by CVE-2021-22278?
PCM600 Update Manager versions 2.1, 2.1.0.4, 2.2, 2.2.0.1, 2.2.0.2, 2.2.0.23, 2.3.0.60, 2.4.20041.1, and 2.4.20119.2 are affected.
What is the severity of CVE-2021-22278?
CVE-2021-22278 has a severity rating of medium with a CVSS score of 6.7.
How can I mitigate the vulnerability?
ABB has released an advisory that provides guidance on mitigating CVE-2021-22278. Please refer to the advisory for specific steps to protect your systems.
Where can I find more information about CVE-2021-22278?
You can find more information about CVE-2021-22278 in the ABB security advisory available at the provided reference links.