Certificate verification vulnerability in Update Manager of PCM600 Engineering Tool
CVE-2021-22278

6.7MEDIUM

Key Information:

Vendor

Abb

Vendor
CVE Published:
28 October 2021

What is CVE-2021-22278?

A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.

Affected Version(s)

PCM600 2.7

PCM600 <= 2.10

PCM600 2.7

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB and Hitachi Energy thank CyTRICS researcher May Chaffin for helping to identify the vulnerabilities and protecting our customers.
.