CVE-2022-1596: ABB Relion REX640 Insufficient file access control
Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1596?
CVE-2022-1596 is a vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 that allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.
How severe is CVE-2022-1596?
CVE-2022-1596 has a severity score of 6.5 (medium).
What software versions are affected by CVE-2022-1596?
CVE-2022-1596 affects ABB REX640 PCL1 firmware up to version 1.0.7, ABB REX640 PCL2 firmware up to version 1.1.4, and ABB REX640 PCL3 firmware up to version 1.2.1.
How can an attacker exploit CVE-2022-1596?
An authenticated attacker can exploit CVE-2022-1596 by launching an attack against the user database file in order to gain control of an affected system node.
Where can I find more information about CVE-2022-1596?
More information about CVE-2022-1596 can be found at: https://search.abb.com/library/Download.aspx?DocumentID=2NGA001421