Description
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.
Published: 2019-06-24
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-16773 The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.
History

No history.

Subscriptions

Abb Board Support Package Un31 Cp620 Cp620-web Cp620-web Firmware Cp620 Firmware Cp630 Cp630-web Cp630-web Firmware Cp630 Firmware Cp635 Cp635-b Cp635-b Firmware Cp635-web Cp635-web Firmware Cp635 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T20:46:45.524Z

Reserved: 2019-01-30T00:00:00.000Z

Link: CVE-2019-7229

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-24T18:15:11.107

Modified: 2024-11-21T04:47:48.030

Link: CVE-2019-7229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses