Description
A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port.
Published: 2021-12-13
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

The problem is corrected in RobotWare version 7.3.2. ABB recommends that customers apply the update at earliest convenience. The update is available for download from RobotStudio.


Vendor Workaround

ABB has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they can help block known attack vectors: • Do not use Connected Services Ethernet port connection until the update has been applied, or • Protect Connected Services Gateway Ethernet port with a firewall, which prevents inbound connections.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-9425 A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port.
History

No history.

Subscriptions

Abb Omnicore C30 Omnicore C30 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2024-09-16T17:38:50.816Z

Reserved: 2021-01-05T00:00:00.000Z

Link: CVE-2021-22279

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-13T16:15:08.590

Modified: 2024-11-21T05:49:50.157

Link: CVE-2021-22279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses