Use of Hard-coded Cryptographic Key in ABB RMC-100 and RMC-100 LITE
CVE-2025-6074
6.3MEDIUM
What is CVE-2025-6074?
A vulnerability exists in ABB RMC-100 and RMC-100 LITE due to the use of hard-coded cryptographic keys. When the REST interface is enabled, attackers with access to the source code and control network can circumvent authentication mechanisms. This exploitation allows unauthorized access to sensitive MQTT configuration data, posing significant risks to system integrity and confidentiality.
Affected Version(s)
RMC-100 2105457-043 <= 2105457-045
RMC-100 LITE 2106229-015 <= 2106229-016
References
CVSS V4
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ABB thanks Claroty Team82 Research for helping to identify the vulnerabilities and protecting our customers