8.8

CVE-2019-10995

ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the HMI interface.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AbbCp651 Firmware Version <= bsp_un30_1.76
   AbbCp651 Version-
AbbCp651-web Firmware Version <= bsp_un30_1.76
   AbbCp651-web Version-
AbbCp661-web Firmware Version <= bsp_un30_1.76
   AbbCp661-web Version-
AbbCp661 Firmware Version <= bsp_un30_1.76
   AbbCp661 Version-
AbbCp665 Firmware Version <= bsp_un30_1.76
   AbbCp665 Version-
AbbCp665-web Firmware Version <= bsp_un30_1.76
   AbbCp665-web Version-
AbbCp676-web Firmware Version <= bsp_un30_1.76
   AbbCp676-web Version-
AbbCp676 Firmware Version <= bsp_un30_1.76
   AbbCp676 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.335
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5.8 6.5 6.4
AV:A/AC:L/Au:N/C:P/I:P/A:P
CWE-798 Use of Hard-coded Credentials

The product contains hard-coded credentials, such as a password or cryptographic key.