PT-2020-12036 · Abb · Abb Irc5
Alfonso Glera
+1
·
Published
2020-07-15
·
Updated
2020-07-24
·
CVE-2020-10287
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ABB IRC5 family with UAS service enabled (affected versions not specified)
Description
The issue concerns default credentials that can be easily found in publicly available manuals for the ABB IRC5 family with UAS service enabled. Although intended to facilitate setup, research has shown that multiple production systems are using these default credentials, posing a significant exposure risk. It is recommended that future deployments should require users to change these defaults to enhance security.
Recommendations
For the ABB IRC5 family with UAS service enabled, consider changing the default credentials to custom ones as a mitigation measure.
As a temporary workaround, restrict access to systems using the default credentials until custom credentials can be set.
Force users to change the default credentials during the initial setup of future deployments to minimize the risk of exposure.
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Abb Irc5