CVE-2025-6074
published 2025-07-03CVE-2025-6074: Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains…
PriorityP338medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.24%
15.7th percentile
Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE.
When the REST interface is enabled by the user, and an attacker gains access to
source code and control network, the attacker can bypass the REST interface authentication and gain access to MQTT configuration data.
This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | rmc-100 | 2105457-043 – 2105457-045 | — |
| abb | rmc-100_lite | 2106229-015 – 2106229-016 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rmg9-687h-jx4v: Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE
ghsa_unreviewed·2025-07-03·CVSS 6.3
CVE-2025-6073 [MEDIUM] CWE-121 GHSA-rmg9-687h-jx4v: Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE
Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE.
When the REST interface is enabled by the user, and an attacker gains access to
the control network, and user/password broker authentication is enabled, and
CVE-2025-6074 is exploited, the attacker can overflow the buffer for username or
password.
This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.
GHSA
GHSA-2f3f-xhh3-hqgg: Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE
ghsa_unreviewed·2025-07-03
CVE-2025-6074 [MEDIUM] CWE-321 GHSA-2f3f-xhh3-hqgg: Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE
Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE.
When the REST interface is enabled by the user, and an attacker gains access to
source code and control network, the attacker can bypass the REST interface authentication and gain access to MQTT configuration data.
This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.
GHSA
GHSA-7896-447p-7w4j: Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE
ghsa_unreviewed·2025-07-03·CVSS 6.3
CVE-2025-6072 [MEDIUM] CWE-121 GHSA-7896-447p-7w4j: Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE
Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE.
When the REST interface is enabled by the user, and an attacker gains access to
the control network, and CVE-2025-6074 is exploited, the attacker can use the
JSON configuration to overflow the date of expiration field.This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.
CISA ICS
ABB RMC-100
cisa_ics·2025-07-15·CVSS 6.5
[MEDIUM] ABB RMC-100
ICS Advisory
##
ABB RMC-100
Release DateJuly 15, 2025
Alert CodeICSA-25-196-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: RMC-100
- Vulnerabilities: Use of Hard-coded Cryptographic Key, Stack-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthenticated access to the MQTT configuration data, cause a denial-of-service condition on the MQTT configuration web server (REST interface), or decrypt encrypted MQTT broker credentials.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
ABB reports the following ve
No detection rules found.
No public exploits indexed.
2025-07-03
Published