Improper Hash Algorithm Vulnerability in ABB PCM600 Application
CVE-2016-4511

2.8LOW

Key Information:

Vendor

Abb

Status
Vendor
CVE Published:
10 June 2016

What is CVE-2016-4511?

The ABB PCM600 application versions prior to 2.7 utilize an inadequate hashing algorithm for the main application password. This vulnerability allows local users with read access to the ACTConfig configuration file to potentially expose sensitive cleartext information. Such exposure could lead to unauthorized access and compromise of the system's integrity.

References

CVSS V3.1

Score:
2.8
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.