CVE-2021-22278
published 2021-10-28CVE-2021-22278: A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.12%
2.5th percentile
A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | pcm600 | >= 2.7 < unspecified | unspecified |
| abb | pcm600 | unspecified – 2.10 | — |
| abb | pcm600_update_manager | — | — |
| abb | pcm600_update_manager | — | — |
| abb | pcm600_update_manager | — | — |
| abb | pcm600_update_manager | — | — |
| abb | pcm600_update_manager | — | — |
| abb | pcm600_update_manager | — | — |
| abb | pcm600_update_manager | — | — |
| abb | pcm600_update_manager | — | — |
| abb | pcm600_update_manager | — | — |
| abb | update_manager | — | — |
| abb | update_manager | — | — |
| abb | update_manager | — | — |
| abb | update_manager | — | — |
| abb | update_manager | — | — |
| abb | update_manager | — | — |
| abb | update_manager | — | — |
| abb | update_manager | — | — |
| abb | update_manager | — | — |
| abb | update_manager | 2.7 – 2.10 | — |
| hitachi_energy | pcm600 | >= 2.7 < unspecified | unspecified |
| hitachi_energy | pcm600 | unspecified – 2.10 | — |
| hitachi_energy | pcm600_update_manager | — | — |
| hitachi_energy | pcm600_update_manager | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m4rm-456c-72hq: A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which ha
ghsa_unreviewed·2022-05-24
CVE-2021-22278 [MEDIUM] CWE-295 GHSA-m4rm-456c-72hq: A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which ha
A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.
CISA ICS
Hitachi Energy PCM600 Update Manager
cisa_ics·2021-12-02·CVSS 6.7
[MEDIUM] Hitachi Energy PCM600 Update Manager
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy PCM600 Update Manager
Last RevisedDecember 02, 2021
Alert CodeICSA-21-336-07
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.7
- Vendor: Hitachi Energy
- Equipment: PCM600 Update Manager
- Vulnerability: Improper Certificate Validation
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to bypass the certificate validation and install an untrusted software package.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of PCM600 Update Manager, an update manager for the PCM600 software (a protection and control
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://search.abb.com/library/Download.aspx?DocumentID=2NGA001142&LanguageCode=en&DocumentPartId=&Action=Launchhttps://search.abb.com/library/Download.aspx?DocumentID=8DBD000056&LanguageCode=en&DocumentPartId=&Action=Launchhttps://search.abb.com/library/Download.aspx?DocumentID=2NGA001142&LanguageCode=en&DocumentPartId=&Action=Launchhttps://search.abb.com/library/Download.aspx?DocumentID=8DBD000056&LanguageCode=en&DocumentPartId=&Action=Launch
2021-10-28
Published