First published: Tue Jun 21 2022(Updated: )
Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Abb Rex640 Pcl1 Firmware | <=1.0.7 | |
ABB REX640 PCL1 | ||
Abb Rex640 Pcl2 Firmware | <1.1.4 | |
ABB REX640 PCL2 | ||
Abb Rex640 Pcl3 Firmware | <1.2.1 | |
ABB REX640 PCL3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1596 is a vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 that allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.
CVE-2022-1596 has a severity score of 6.5 (medium).
CVE-2022-1596 affects ABB REX640 PCL1 firmware up to version 1.0.7, ABB REX640 PCL2 firmware up to version 1.1.4, and ABB REX640 PCL3 firmware up to version 1.2.1.
An authenticated attacker can exploit CVE-2022-1596 by launching an attack against the user database file in order to gain control of an affected system node.
More information about CVE-2022-1596 can be found at: https://search.abb.com/library/Download.aspx?DocumentID=2NGA001421