Vulnerability Name: | CVE-2016-4511 (CCN-113755) | ||||||||||||
Assigned: | 2016-05-31 | ||||||||||||
Published: | 2016-05-31 | ||||||||||||
Updated: | 2016-06-17 | ||||||||||||
Summary: | ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leveraging read access to the ACTConfig configuration file. | ||||||||||||
CVSS v3 Severity: | 2.8 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N) 2.5 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-310 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-4511 Source: CCN Type: ABB Web site Protection and control IED manager PCM600 Source: XF Type: UNKNOWN abb-pcm600-cve20164511-weak-security(113755) Source: CCN Type: ICSA-16-152-02 ABB PCM600 Vulnerabilities Source: MISC Type: Third Party Advisory, US Government Resource https://ics-cert.us-cert.gov/advisories/ICSA-16-152-02 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |