CVE-2019-7229
ABB HMI Missing Signature Verification
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.
La HMI CP635 de ABB usa dos métodos de transmisión diferentes para actualizar su firmware y sus componentes de software: "Utilization of USB/SD Card to flash the device" y "Remote provisioning process via ABB Panel Builder 600 over FTP.". Ninguno de estos métodos de transmisión implementa ninguna forma de cifrado o comprobación de autenticidad contra los nuevos archivos binarios del software HMI del firmware.
ABB HMI fails to perform any signature validation checking during two different transmission methods for upgrade.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-30 CVE Reserved
- 2019-06-21 CVE Published
- 2024-07-22 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-494: Download of Code Without Integrity Check
CAPEC
References (5)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Abb Search vendor "Abb" | Cp620 Firmware Search vendor "Abb" for product "Cp620 Firmware" | < 2.8.0.424 Search vendor "Abb" for product "Cp620 Firmware" and version " < 2.8.0.424" | - |
Affected
| in | Abb Search vendor "Abb" | Cp620 Search vendor "Abb" for product "Cp620" | - | - |
Safe
|
Abb Search vendor "Abb" | Cp620-web Firmware Search vendor "Abb" for product "Cp620-web Firmware" | < 2.8.0.424 Search vendor "Abb" for product "Cp620-web Firmware" and version " < 2.8.0.424" | - |
Affected
| in | Abb Search vendor "Abb" | Cp620-web Search vendor "Abb" for product "Cp620-web" | - | - |
Safe
|
Abb Search vendor "Abb" | Cp630 Firmware Search vendor "Abb" for product "Cp630 Firmware" | < 2.0.8.424 Search vendor "Abb" for product "Cp630 Firmware" and version " < 2.0.8.424" | - |
Affected
| in | Abb Search vendor "Abb" | Cp630 Search vendor "Abb" for product "Cp630" | - | - |
Safe
|
Abb Search vendor "Abb" | Cp630-web Firmware Search vendor "Abb" for product "Cp630-web Firmware" | < 2.8.0.424 Search vendor "Abb" for product "Cp630-web Firmware" and version " < 2.8.0.424" | - |
Affected
| in | Abb Search vendor "Abb" | Cp630-web Search vendor "Abb" for product "Cp630-web" | - | - |
Safe
|
Abb Search vendor "Abb" | Cp635 Firmware Search vendor "Abb" for product "Cp635 Firmware" | < 2.8.0.424 Search vendor "Abb" for product "Cp635 Firmware" and version " < 2.8.0.424" | - |
Affected
| in | Abb Search vendor "Abb" | Cp635 Search vendor "Abb" for product "Cp635" | - | - |
Safe
|
Abb Search vendor "Abb" | Cp635-b Firmware Search vendor "Abb" for product "Cp635-b Firmware" | < 2.8.0.424 Search vendor "Abb" for product "Cp635-b Firmware" and version " < 2.8.0.424" | - |
Affected
| in | Abb Search vendor "Abb" | Cp635-b Search vendor "Abb" for product "Cp635-b" | - | - |
Safe
|
Abb Search vendor "Abb" | Cp635-web Firmware Search vendor "Abb" for product "Cp635-web Firmware" | < 2.8.0.424 Search vendor "Abb" for product "Cp635-web Firmware" and version " < 2.8.0.424" | - |
Affected
| in | Abb Search vendor "Abb" | Cp635-web Search vendor "Abb" for product "Cp635-web" | - | - |
Safe
|
Abb Search vendor "Abb" | Board Support Package Un31 Search vendor "Abb" for product "Board Support Package Un31" | < 2.31 Search vendor "Abb" for product "Board Support Package Un31" and version " < 2.31" | - |
Affected
|