PT-2025-27818 · Abb · Abb Rmc-100+1

Published

2025-07-03

·

Updated

2025-07-15

·

CVE-2025-6074

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: ABB RMC-100 versions 2105457-043 through 2105457-045 ABB RMC-100 LITE versions 2106229-015 through 2106229-016
Description: The issue is related to the use of a hard-coded cryptographic key. When the REST interface is enabled and an attacker gains access to the source code and control network, they can bypass the REST interface authentication and gain access to MQTT configuration data.
Recommendations: For ABB RMC-100 versions 2105457-043 through 2105457-045, consider disabling the REST interface until a patch is available to prevent exploitation. For ABB RMC-100 LITE versions 2106229-015 through 2106229-016, restrict access to the MQTT configuration data to minimize the risk of unauthorized access. As a temporary workaround, consider restricting network access to the affected devices until a fix is provided.

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-08251
CVE-2025-6074

Affected Products

Abb Rmc-100
Abb Rmc-100 Lite