HIGH · 8.3

CVE-2019-7229

The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB...

Vulnerability Description

The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.

CVSS Score

8.3

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AbbBoard Support Package Un31< 2.31
AbbCp620 Firmware< 2.8.0.424
AbbCp620-
AbbCp620-Web Firmware< 2.8.0.424
AbbCp620-Web-
AbbCp630 Firmware< 2.0.8.424
AbbCp630-
AbbCp630-Web Firmware< 2.8.0.424
AbbCp630-Web-
AbbCp635 Firmware< 2.8.0.424
AbbCp635-
AbbCp635-B Firmware< 2.8.0.424
AbbCp635-B-
AbbCp635-Web Firmware< 2.8.0.424
AbbCp635-Web-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-7229?

CVE-2019-7229 is a vulnerability with a CVSS score of 8.3 (HIGH). The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB...

How severe is CVE-2019-7229?

CVE-2019-7229 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-7229?

Check the references section above for vendor advisories and patch information. Affected products include: Abb Board Support Package Un31, Abb Cp620 Firmware, Abb Cp620, Abb Cp620-Web Firmware, Abb Cp620-Web.