// For flags

CVE-2021-22278

Certificate verification vulnerability in Update Manager of PCM600 Engineering Tool

Severity Score

6.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.

Una vulnerabilidad de comprobaciĆ³n de certificados en PCM600 Update Manager permite a un atacante conseguir que se instalen paquetes de software no deseados en el ordenador que presenta instalado el PCM600

*Credits: ABB and Hitachi Energy thank CyTRICS researcher May Chaffin for helping to identify the vulnerabilities and protecting our customers.
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-01-05 CVE Reserved
  • 2021-10-28 CVE Published
  • 2023-05-21 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-295: Improper Certificate Validation
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Abb
Search vendor "Abb"
Update Manager
Search vendor "Abb" for product "Update Manager"
>= 2.7 <= 2.10
Search vendor "Abb" for product "Update Manager" and version " >= 2.7 <= 2.10"
-
Affected
in Hitachienergy
Search vendor "Hitachienergy"
Pcm600
Search vendor "Hitachienergy" for product "Pcm600"
--
Safe
Abb
Search vendor "Abb"
Update Manager
Search vendor "Abb" for product "Update Manager"
2.1
Search vendor "Abb" for product "Update Manager" and version "2.1"
-
Affected
Abb
Search vendor "Abb"
Update Manager
Search vendor "Abb" for product "Update Manager"
2.1.0.4
Search vendor "Abb" for product "Update Manager" and version "2.1.0.4"
-
Affected
Abb
Search vendor "Abb"
Update Manager
Search vendor "Abb" for product "Update Manager"
2.2
Search vendor "Abb" for product "Update Manager" and version "2.2"
-
Affected
Abb
Search vendor "Abb"
Update Manager
Search vendor "Abb" for product "Update Manager"
2.2.0.1
Search vendor "Abb" for product "Update Manager" and version "2.2.0.1"
-
Affected
Abb
Search vendor "Abb"
Update Manager
Search vendor "Abb" for product "Update Manager"
2.2.0.2
Search vendor "Abb" for product "Update Manager" and version "2.2.0.2"
-
Affected
Abb
Search vendor "Abb"
Update Manager
Search vendor "Abb" for product "Update Manager"
2.2.0.23
Search vendor "Abb" for product "Update Manager" and version "2.2.0.23"
-
Affected
Abb
Search vendor "Abb"
Update Manager
Search vendor "Abb" for product "Update Manager"
2.3.0.60
Search vendor "Abb" for product "Update Manager" and version "2.3.0.60"
-
Affected
Abb
Search vendor "Abb"
Update Manager
Search vendor "Abb" for product "Update Manager"
2.4.20041.1
Search vendor "Abb" for product "Update Manager" and version "2.4.20041.1"
-
Affected
Abb
Search vendor "Abb"
Update Manager
Search vendor "Abb" for product "Update Manager"
2.4.20119.2
Search vendor "Abb" for product "Update Manager" and version "2.4.20119.2"
-
Affected