CVE-2021-22278

Severity
6.7MEDIUM
EPSS
0.0%
top 95.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 28
Latest updateMay 24

Description

A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5abb/pcm600_update_manager9 versions+8
CVEListV5hitachi_energy/pcm600_update_manager9 versions+8
CVEListV5abb/pcm6002.7unspecified+1
CVEListV5hitachi_energy/pcm6002.7unspecified+1
NVDabb/update_manager2.72.10+9

🔴Vulnerability Details

2
GHSA
GHSA-m4rm-456c-72hq: A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which ha2022-05-24
CVEList
Certificate verification vulnerability in Update Manager of PCM600 Engineering Tool2021-10-28