First published: Tue May 31 2022(Updated: )
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
ABB e-Design | <=1.12.2.0004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28702 is an Incorrect Default Permissions vulnerability in ABB e-Design that allows an attacker to install malicious software with SYSTEM permissions, compromising the confidentiality, integrity, and availability of the target machine.
ABB e-Design versions up to and including 1.12.2.0004 are affected by CVE-2022-28702.
CVE-2022-28702 has a severity score of 5.5, which is considered medium.
An attacker can exploit CVE-2022-28702 by leveraging the incorrect default permissions to install malicious software with SYSTEM privileges on the target machine.
ABB has released a fix for CVE-2022-28702. It is recommended to update to the latest version of ABB e-Design to mitigate this vulnerability.