// For flags

CVE-2019-7229

ABB HMI Missing Signature Verification

Severity Score

8.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.

La HMI CP635 de ABB usa dos métodos de transmisión diferentes para actualizar su firmware y sus componentes de software: "Utilization of USB/SD Card to flash the device" y "Remote provisioning process via ABB Panel Builder 600 over FTP.". Ninguno de estos métodos de transmisión implementa ninguna forma de cifrado o comprobación de autenticidad contra los nuevos archivos binarios del software HMI del firmware.

ABB HMI fails to perform any signature validation checking during two different transmission methods for upgrade.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Adjacent
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-30 CVE Reserved
  • 2019-06-21 CVE Published
  • 2024-07-22 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-494: Download of Code Without Integrity Check
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Abb
Search vendor "Abb"
Cp620 Firmware
Search vendor "Abb" for product "Cp620 Firmware"
< 2.8.0.424
Search vendor "Abb" for product "Cp620 Firmware" and version " < 2.8.0.424"
-
Affected
in Abb
Search vendor "Abb"
Cp620
Search vendor "Abb" for product "Cp620"
--
Safe
Abb
Search vendor "Abb"
Cp620-web Firmware
Search vendor "Abb" for product "Cp620-web Firmware"
< 2.8.0.424
Search vendor "Abb" for product "Cp620-web Firmware" and version " < 2.8.0.424"
-
Affected
in Abb
Search vendor "Abb"
Cp620-web
Search vendor "Abb" for product "Cp620-web"
--
Safe
Abb
Search vendor "Abb"
Cp630 Firmware
Search vendor "Abb" for product "Cp630 Firmware"
< 2.0.8.424
Search vendor "Abb" for product "Cp630 Firmware" and version " < 2.0.8.424"
-
Affected
in Abb
Search vendor "Abb"
Cp630
Search vendor "Abb" for product "Cp630"
--
Safe
Abb
Search vendor "Abb"
Cp630-web Firmware
Search vendor "Abb" for product "Cp630-web Firmware"
< 2.8.0.424
Search vendor "Abb" for product "Cp630-web Firmware" and version " < 2.8.0.424"
-
Affected
in Abb
Search vendor "Abb"
Cp630-web
Search vendor "Abb" for product "Cp630-web"
--
Safe
Abb
Search vendor "Abb"
Cp635 Firmware
Search vendor "Abb" for product "Cp635 Firmware"
< 2.8.0.424
Search vendor "Abb" for product "Cp635 Firmware" and version " < 2.8.0.424"
-
Affected
in Abb
Search vendor "Abb"
Cp635
Search vendor "Abb" for product "Cp635"
--
Safe
Abb
Search vendor "Abb"
Cp635-b Firmware
Search vendor "Abb" for product "Cp635-b Firmware"
< 2.8.0.424
Search vendor "Abb" for product "Cp635-b Firmware" and version " < 2.8.0.424"
-
Affected
in Abb
Search vendor "Abb"
Cp635-b
Search vendor "Abb" for product "Cp635-b"
--
Safe
Abb
Search vendor "Abb"
Cp635-web Firmware
Search vendor "Abb" for product "Cp635-web Firmware"
< 2.8.0.424
Search vendor "Abb" for product "Cp635-web Firmware" and version " < 2.8.0.424"
-
Affected
in Abb
Search vendor "Abb"
Cp635-web
Search vendor "Abb" for product "Cp635-web"
--
Safe
Abb
Search vendor "Abb"
Board Support Package Un31
Search vendor "Abb" for product "Board Support Package Un31"
< 2.31
Search vendor "Abb" for product "Board Support Package Un31" and version " < 2.31"
-
Affected