CVE-2019-7229
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.
Published:Jun 24, 2019
Last Modified:Nov 21, 2024
EPS:Jun 24, 2019
EPSS Score:0.00085
CVSS Score:8.3
Affected Products
Vendor
Product
Action
Vendor
Abb
Product
Board Support Package Un31
Abb
Board Support Package Un31
Vendor
Abb
Product
Cp620
Abb
Cp620
Vendor
Abb
Product
Cp620-web
Abb
Cp620-web
Vendor
Abb
Product
Cp620-web Firmware
Abb
Cp620-web Firmware
Vendor
Abb
Product
Cp620 Firmware
Abb
Cp620 Firmware
Vendor
Abb
Product
Cp630
Abb
Cp630
Vendor
Abb
Product
Cp630-web
Abb
Cp630-web
Vendor
Abb
Product
Cp630-web Firmware
Abb
Cp630-web Firmware
Vendor
Abb
Product
Cp630 Firmware
Abb
Cp630 Firmware
Vendor
Abb
Product
Cp635
Abb
Cp635
Vendor
Abb
Product
Cp635-b
Abb
Cp635-b
Vendor
Abb
Product
Cp635-b Firmware
Abb
Cp635-b Firmware
Vendor
Abb
Product
Cp635-web
Abb
Cp635-web
Vendor
Abb
Product
Cp635-web Firmware
Abb
Cp635-web Firmware
Vendor
Abb
Product
Cp635 Firmware
Abb
Cp635 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
