Vulnerability identifier: #VU16606
Vulnerability risk: Low
CVSSv3.1: 9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:U/RC:C]
CVE-ID:
CWE-ID:
CWE-306
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
GATE-E2
Hardware solutions /
Firmware
GATE-E1
Hardware solutions /
Firmware
Vendor: ABB
Description
The disclosed vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due the devices do not allow authentication to be configured on administrative telnet or web interfaces. A remote attacker can bypass authentication to conduct device resets, read or modify registers, and change configuration settings such as IP addresses.
Mitigation
ABB will not be releasing updated firmware, as both GATE-E1 and GATE-E2 have reached end of life (EOL). ABB recommends implementing defense-in-depth principles to minimize the risk that vulnerabilities are exploited.
Vulnerable software versions
GATE-E2: All versions
GATE-E1: All versions
External links
http://applied-risk.com/application/files/8615/4505/6727/Advisory_AR2018008_-_ABB_GATE_E1-E2_Multiple_Vulnerabilities_1.0.pdf
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.