PT-2020-11147 · Abb · Abb Microscada Pro Sys600

Published

2020-04-29

·

Updated

2023-05-16

·

CVE-2019-5620

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ABB MicroSCADA Pro SYS600 version 9.3
Description The issue is related to missing authentication for a critical function, as described by the instance of CWE-306. This means that the software lacks proper authentication mechanisms, potentially allowing unauthorized access to critical functions.
Recommendations For ABB MicroSCADA Pro SYS600 version 9.3, consider implementing proper authentication mechanisms for critical functions to prevent unauthorized access. As a temporary workaround, restrict access to critical functions until a proper authentication mechanism is in place. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2019-5620

Affected Products

Abb Microscada Pro Sys600