CVE-2022-0010
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to exploit this vulnerability to gain control of system nodes. This issue affects QCS 800xA: from 1.0;0 through 6.1SP2; QCS AC450: from 1.0;0 through 5.1SP2; Platform Engineering Tools: from 1.0:0 through 2.3.0.
Published:May 22, 2023
Last Modified:Jan 21, 2025
EPS:May 22, 2023
EPSS Score:0.00061
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Abb
Product
Platform Engineering Tools
Abb
Platform Engineering Tools
Vendor
Abb
Product
Qcs 800xa
Abb
Qcs 800xa
Vendor
Abb
Product
Qcs 800xa Firmware
Abb
Qcs 800xa Firmware
Vendor
Abb
Product
Qcs Ac450
Abb
Qcs Ac450
Vendor
Abb
Product
Qcs Ac450 Firmware
Abb
Qcs Ac450 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
