CVE-2016-4524
published 2016-06-10CVE-2016-4524: ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive…
PriorityP422medium6.5CVSS 3.0
AVLACLPRLUINSCCHINAN
EPSS
0.29%
20.4th percentile
ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | pcm600 | <= 2.6 | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8mqx-rxrp-v4x5: ABB PCM600 before 2
ghsa_unreviewed·2022-05-17
CVE-2016-4524 [MEDIUM] CWE-284 GHSA-8mqx-rxrp-v4x5: ABB PCM600 before 2
ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.
CISA ICS
ABB PCM600 Vulnerabilities
cisa_ics·2018-08-23
ABB PCM600 Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB PCM600 Vulnerabilities
Last RevisedAugust 23, 2018
Alert CodeICSA-16-152-02
## OVERVIEW
ABB has identified one use of password hash with insufficient computational effort and three insufficiently protected credentials vulnerabilities in ABB’s PCM600. These vulnerabilities were reported directly to ABB by Ilya Karpov from Positive Technologies. ABB has produced a new version to mitigate these vulnerabilities.
## AFFECTED PRODUCTS
ABB reports that the vulnerabilities affect the following products:
- PCM600 up to and including Version 2.6
## IMPACT
An attacker who successf
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-06-10
Published