CVE-2016-4511
published 2016-06-10CVE-2016-4511: ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext…
PriorityP47low2.8CVSS 3.0
AVLACLPRLUIRSUCLINAN
EPSS
0.30%
22.2th percentile
ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leveraging read access to the ACTConfig configuration file.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | pcm600 | <= 2.6 | — |
CVSS provenance
nvdv3.02.8LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB PCM600 Vulnerabilities
cisa_ics·2018-08-23
ABB PCM600 Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB PCM600 Vulnerabilities
Last RevisedAugust 23, 2018
Alert CodeICSA-16-152-02
## OVERVIEW
ABB has identified one use of password hash with insufficient computational effort and three insufficiently protected credentials vulnerabilities in ABB’s PCM600. These vulnerabilities were reported directly to ABB by Ilya Karpov from Positive Technologies. ABB has produced a new version to mitigate these vulnerabilities.
## AFFECTED PRODUCTS
ABB reports that the vulnerabilities affect the following products:
- PCM600 up to and including Version 2.6
## IMPACT
An attacker who successf
GHSA
GHSA-7xf7-47f3-rm7v: ABB PCM600 before 2
ghsa_unreviewed·2022-05-17
CVE-2016-4511 [LOW] GHSA-7xf7-47f3-rm7v: ABB PCM600 before 2
ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leveraging read access to the ACTConfig configuration file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-06-10
Published