SB2018102426 - Authentication bypass in ABB M2M ETHERNET



SB2018102426 - Authentication bypass in ABB M2M ETHERNET

Published: October 24, 2018

Security Bulletin ID SB2018102426
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Authentication bypass (CVE-ID: CVE-2018-17926)

The vulnerability allows an adjacent attacker to bypass authentication on the target system.

The vulnerability exists due to improper authentication. An adjacent attacker can bypass the user authentication mechanism and upload a malicious language file.


Remediation

Install update from vendor's website.