Weak Password Storage Vulnerability in ABB PCM600 Software
CVE-2016-4516

3.3LOW

Key Information:

Vendor

Abb

Status
Vendor
CVE Published:
10 June 2016

What is CVE-2016-4516?

The ABB PCM600 software versions prior to 2.7 contain a vulnerability that improperly handles the storage of the main application password after it is changed. This oversight allows local users to potentially access sensitive information through undisclosed methods, thereby compromising the security of the system. Organizations using vulnerable versions of PCM600 should take immediate action to mitigate this risk by updating to the latest version.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.