A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-9425 A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port.
Fixes

Solution

The problem is corrected in RobotWare version 7.3.2. ABB recommends that customers apply the update at earliest convenience. The update is available for download from RobotStudio.


Workaround

ABB has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they can help block known attack vectors: • Do not use Connected Services Ethernet port connection until the update has been applied, or • Protect Connected Services Gateway Ethernet port with a firewall, which prevents inbound connections.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2024-09-16T17:38:50.816Z

Reserved: 2021-01-05T00:00:00

Link: CVE-2021-22279

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-13T16:15:08.590

Modified: 2024-11-21T05:49:50.157

Link: CVE-2021-22279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.