PT-2022-6499 · Abb · Abb Rccmd

Published

2022-11-23

·

Updated

2023-07-10

·

CVE-2022-4126

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ABB RCCMD versions prior to 4.40 230207
Description The issue is related to the use of default passwords in the ABB RCCMD client-server application for managing uninterruptible power supplies. This could allow a remote attacker to execute arbitrary code or gain full control over the application by trying common or default usernames and passwords.
Recommendations For versions prior to 4.40 230207, update to version 4.40 230207 or later to resolve the issue. As a temporary workaround, consider changing the default passwords to unique, strong passwords until a patch is applied. Restrict access to the application to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-01779
CVE-2022-4126

Affected Products

Abb Rccmd