SB2018102425 - Authentication bypass in ABB CMS-770



SB2018102425 - Authentication bypass in ABB CMS-770

Published: October 24, 2018

Security Bulletin ID SB2018102425
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Authentication bypass (CVE-ID: CVE-2018-17928)

The vulnerability allows an adjacent attacker to bypass authentication on the target system.

The vulnerability exists due to improper authentication. An adjacent attacker can bypass the user authentication mechanism and read sensitive configuration files that the attacker can use to take over the entire device.


Remediation

Install update from vendor's website.