CVE-2019-7229

HIGHCVSS 8.3/10EPSS 1.10%

Last modified

CVE-2019-7229 is a high-severity vulnerability rated 8.3/10 on the CVSS scale. The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.. EPSS estimates a 1.10% chance of exploitation in the next 30 days.

Description

The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.

Metrics

CVSS 3.1
8.3/10

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS Probability
1.10%

61.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AbbBoard Support Package Un31< 2.31
AbbCp620 Firmware< 2.8.0.424
AbbCp620-Web Firmware< 2.8.0.424
AbbCp630 Firmware< 2.0.8.424
AbbCp630-Web Firmware< 2.8.0.424
AbbCp635 Firmware< 2.8.0.424
AbbCp635-B Firmware< 2.8.0.424
AbbCp635-Web Firmware< 2.8.0.424

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-7229?
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.
How severe is CVE-2019-7229?
CVE-2019-7229 has a CVSS score of 8.3/10 (HIGH severity). The EPSS model estimates a 1.10% probability of exploitation in the next 30 days.
How do I fix CVE-2019-7229?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-7229?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST