The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Abb
Subscribe
|
Board Support Package Un31
Subscribe
Cp620
Subscribe
Cp620-web
Subscribe
Cp620-web Firmware
Subscribe
Cp620 Firmware
Subscribe
Cp630
Subscribe
Cp630-web
Subscribe
Cp630-web Firmware
Subscribe
Cp630 Firmware
Subscribe
Cp635
Subscribe
Cp635-b
Subscribe
Cp635-b Firmware
Subscribe
Cp635-web
Subscribe
Cp635-web Firmware
Subscribe
Cp635 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-16773 | The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T20:46:45.524Z
Reserved: 2019-01-30T00:00:00
Link: CVE-2019-7229
No data.
Status : Modified
Published: 2019-06-24T18:15:11.107
Modified: 2024-11-21T04:47:48.030
Link: CVE-2019-7229
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD