CVE-2019-7225
Last modified
CVE-2019-7225 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. EPSS estimates a 2.90% chance of exploitation in the next 30 days.
Description
The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. These credentials are the idal123 password for the IdalMaster account, and the exor password for the exor account. These credentials are used over both HTTP(S) and FTP. There is no option to disable or change these undocumented credentials. An attacker can use these credentials to login to ABB HMI to read/write HMI configuration files and also to reset the device. This affects ABB CP635 HMI, CP600 HMIClient, Panel Builder 600, IDAL FTP server, IDAL HTTP server, and multiple other HMI components.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Abb | Cp620 Firmware | <= 1.76 |
| Abb | Cp620-Web Firmware | <= 1.76 |
| Abb | Cp630 Firmware | <= 1.76 |
| Abb | Cp630-Web Firmware | <= 1.76 |
| Abb | Cp635 Firmware | <= 1.76 |
| Abb | Cp635-B Firmware | <= 1.76 |
| Abb | Cp635-Web Firmware | <= 1.76 |
| Abb | Pb610 Firmware | >= 1.91, <= 2.8.0.3674 |
| Abb | Cp651-Web Firmware | <= 1.76 |
| Abb | Cp661 Firmware | <= 1.76 |
| Abb | Cp661-Web Firmware | <= 1.76 |
| Abb | Cp665 Firmware | <= 1.76 |
| Abb | Cp665-Web Firmware | <= 1.76 |
| Abb | Cp676 Firmware | <= 1.76 |
| Abb | Cp676-Web Firmware | <= 1.76 |
| Abb | Cp651 Firmware | <= 1.76 |
References
- http://packetstormsecurity.com/files/153397/ABB-HMI-Hardcoded-Credentials.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Jun/38Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108922Third Party Advisory, VDB Entry
- https://www.darkmatter.ae/xen1thlabs/abb-hmi-hardcoded-credentials-vulnerability-xl-19-009/Exploit, Patch, Third Party Advisory
- http://packetstormsecurity.com/files/153397/ABB-HMI-Hardcoded-Credentials.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Jun/38Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108922Third Party Advisory, VDB Entry
- https://www.darkmatter.ae/xen1thlabs/abb-hmi-hardcoded-credentials-vulnerability-xl-19-009/Exploit, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-7225?
How severe is CVE-2019-7225?
How do I fix CVE-2019-7225?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-7218Citrix ShareFile before 19.23 allows a downgrade from two-fa…
- CVE-2019-7219Unauthenticated reflected cross-site scripting (XSS) exists …
- CVE-2019-7220X-Cart V5 is vulnerable to XSS via the CategoryFilter2 param…
- CVE-2019-7221The KVM implementation in the Linux kernel through 4.20.5 ha…
- CVE-2019-7222The KVM implementation in the Linux kernel through 4.20.5 ha…5.5
- CVE-2019-7223InvoicePlane 1.5 has stored XSS via the index.php/invoices/a…
- CVE-2019-7226The ABB IDAL HTTP server CGI interface contains a URL that a…8.8
- CVE-2019-7227In the ABB IDAL FTP server, an authenticated attacker can tr…7.3
- CVE-2019-7228The ABB IDAL HTTP server mishandles format strings in a user…8.8
- CVE-2019-7229The ABB CP635 HMI uses two different transmission methods to…8.3
- CVE-2019-7230The ABB IDAL FTP server mishandles format strings in a usern…8.8
- CVE-2019-7231The ABB IDAL FTP server is vulnerable to a buffer overflow w…5.7
Are you affected by CVE-2019-7225?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
