PT-2025-27818 · Abb · Abb Rmc-100+1
Published
2025-07-03
·
Updated
2025-07-15
·
CVE-2025-6074
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
ABB RMC-100 versions 2105457-043 through 2105457-045
ABB RMC-100 LITE versions 2106229-015 through 2106229-016
Description:
The issue is related to the use of a hard-coded cryptographic key. When the REST interface is enabled and an attacker gains access to the source code and control network, they can bypass the REST interface authentication and gain access to MQTT configuration data.
Recommendations:
For ABB RMC-100 versions 2105457-043 through 2105457-045, consider disabling the REST interface until a patch is available to prevent exploitation.
For ABB RMC-100 LITE versions 2106229-015 through 2106229-016, restrict access to the MQTT configuration data to minimize the risk of unauthorized access.
As a temporary workaround, consider restricting network access to the affected devices until a fix is provided.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abb Rmc-100
Abb Rmc-100 Lite