PT-2022-13993 · Abb · Abb Rex640 Pcl2+2
Published
2022-06-21
·
Updated
2022-06-29
·
CVE-2022-1596
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ABB REX640 PCL1
ABB REX640 PCL2
ABB REX640 PCL3
Description
The issue allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node due to incorrect permission assignment for a critical resource.
Recommendations
For ABB REX640 PCL1, update the permission settings to restrict access to the user database file.
For ABB REX640 PCL2, adjust the access controls to prevent unauthorized modifications to the system node.
For ABB REX640 PCL3, reconfigure the system to limit the privileges of authenticated attackers.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abb Rex640 Pcl1
Abb Rex640 Pcl2
Abb Rex640 Pcl3