Vulnerability in ABB PCM600 Allows Local Users to Access Sensitive Passwords
CVE-2016-4524

6.5MEDIUM

Key Information:

Vendor

Abb

Status
Vendor
CVE Published:
10 June 2016

What is CVE-2016-4524?

The ABB PCM600 software, prior to version 2.7, has a security flaw that improperly manages the storage of OPC Server IEC61850 passwords. This vulnerability permits local users to potentially gain unauthorized access to sensitive information under certain conditions. The precise methods by which this information can be accessed remain unclear, creating potential exposure risks for organizations using affected versions.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.