Abb Rex640 Pcl2 Firmware vulnerabilities

3 known vulnerabilities affecting abb/rex640_pcl2_firmware.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-2876MEDIUMCVSS 6.1≥ 1.0.0, < 1.1.42023-06-13
CVE-2023-2876 [LOW] CWE-1004 CVE-2023-2876: Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB RE Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0 before 1.2.1.
nvd
CVE-2021-22283MEDIUMCVSS 5.5fixed in 1.1.42023-02-28
CVE-2021-22283 [MEDIUM] CWE-665 CVE-2021-22283: Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion prote Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 series IEC 4.0 FP1, ABB Relion protection relays - 615 series CN 4.0 FP1, ABB Relion protection relays - 615 series IEC 5.0, ABB Relion protection relays - 615 series IEC 5.0 FP1, ABB Relion protection relays - 620 series IEC/CN 2.0
nvd
CVE-2022-1596MEDIUMCVSS 6.5fixed in 1.1.42022-06-21
CVE-2022-1596 [MEDIUM] CWE-732 CVE-2022-1596: Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.
nvd