CVE-2016-4516
published 2016-06-10CVE-2016-4516: ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via…
PriorityP49low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.30%
21.8th percentile
ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | pcm600 | <= 2.6 | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB PCM600 Vulnerabilities
cisa_ics·2018-08-23
ABB PCM600 Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB PCM600 Vulnerabilities
Last RevisedAugust 23, 2018
Alert CodeICSA-16-152-02
## OVERVIEW
ABB has identified one use of password hash with insufficient computational effort and three insufficiently protected credentials vulnerabilities in ABB’s PCM600. These vulnerabilities were reported directly to ABB by Ilya Karpov from Positive Technologies. ABB has produced a new version to mitigate these vulnerabilities.
## AFFECTED PRODUCTS
ABB reports that the vulnerabilities affect the following products:
- PCM600 up to and including Version 2.6
## IMPACT
An attacker who successf
Red Hat
jasper: heap buffer overflow in jpc_dec_cp_setfromcox() (rejected duplicate of CVE-2011-4516)
vendor_redhat·2016-10-17·CVSS 6.8
CVE-2016-8880 [MEDIUM] CWE-122 jasper: heap buffer overflow in jpc_dec_cp_setfromcox() (rejected duplicate of CVE-2011-4516)
jasper: heap buffer overflow in jpc_dec_cp_setfromcox() (rejected duplicate of CVE-2011-4516)
[REJECTED CVE] A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 compressed image files. An attacker could create a malicious JPEG 2000 compressed image file that, when opened, would cause applications that use JasPer (such as Nautilus) to crash or, potentially, execute arbitrary code.
Statement: This flaw was found to be a duplicate of CVE-2011-4516. Please see https://access.redhat.com/security/cve/CVE-2011-4516 for information about affected products and security errata.
Package: netpbm (Red Hat Enterprise Linux 5) - Not affected
Package: jasper (Red Hat Enterprise Linux 6) - Not affected
Package: jasper (Red Hat Enterprise Linux 7) - Not affected
Package: mi
GHSA
GHSA-3p2g-r477-j4fj: ABB PCM600 before 2
ghsa_unreviewed·2022-05-17
CVE-2016-4516 [LOW] CWE-200 GHSA-3p2g-r477-j4fj: ABB PCM600 before 2
ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-06-10
Published