PT-2020-12036 · Abb · Abb Irc5

Alfonso Glera

+1

·

Published

2020-07-15

·

Updated

2020-07-24

·

CVE-2020-10287

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions ABB IRC5 family with UAS service enabled (affected versions not specified)
Description The issue concerns default credentials that can be easily found in publicly available manuals for the ABB IRC5 family with UAS service enabled. Although intended to facilitate setup, research has shown that multiple production systems are using these default credentials, posing a significant exposure risk. It is recommended that future deployments should require users to change these defaults to enhance security.
Recommendations For the ABB IRC5 family with UAS service enabled, consider changing the default credentials to custom ones as a mitigation measure. As a temporary workaround, restrict access to systems using the default credentials until custom credentials can be set. Force users to change the default credentials during the initial setup of future deployments to minimize the risk of exposure.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10287

Affected Products

Abb Irc5