Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-24885 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node. |
Fixes
Solution
No solution given by the vendor.
Workaround
Although these workarounds will not correct the underlying vulnerability, they can help blocking known attack vectors. • Limit the HTTP(s) and FTP(S) to a local network by a firewall • Use a next generation (OSI layer 7) firewall for blocking the traffic to the userdb.xml file • Disable remote WHMI and FTP(S) and use local HMI only
References
History
No history.

Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2024-09-16T23:11:43.087Z
Reserved: 2022-05-05T00:00:00
Link: CVE-2022-1596

No data.

Status : Modified
Published: 2022-06-21T15:15:08.247
Modified: 2024-11-21T06:41:02.593
Link: CVE-2022-1596

No data.

No data.