ID

VAR-201411-0415


CVE

CVE-2014-5430


TITLE

ABB RobotStudio and Test Signal Viewer Vulnerability gained in

Trust: 0.8

sources: JVNDB: JVNDB-2014-005292

DESCRIPTION

Untrusted search path vulnerability in ABB RobotStudio 5.6x before 5.61.02 and Test Signal Viewer 1.5 allows local users to gain privileges via a Trojan horse DLL that is accessed as a result of incorrect DLL configuration by an optional installation program. Supplementary information : CWE Vulnerability type by CWE-427: Uncontrolled Search Path Element ( Uncontrolled search path elements ) Has been identified. ABB is a leader in power and automation technology. ABB is committed to providing efficient and reliable solutions for a wide range of industries in terms of energy efficiency, industrial productivity and grid stability. A local code execution vulnerability exists in multiple ABB products that can be exploited by local attackers to execute arbitrary code. RobotStudio is a set of robot offline programming and simulation software

Trust: 2.7

sources: NVD: CVE-2014-5430 // JVNDB: JVNDB-2014-005292 // CNVD: CNVD-2014-08129 // BID: 70907 // IVD: ba9f79d4-2351-11e6-abef-000c29c66e3d // VULHUB: VHN-73371

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: ba9f79d4-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-08129

AFFECTED PRODUCTS

vendor:abbmodel:test signal viewerscope:eqversion:1.5

Trust: 2.7

vendor:abbmodel:robotstudioscope:eqversion:5.60

Trust: 1.9

vendor:abbmodel:robotstudioscope:eqversion:5.61.01

Trust: 1.6

vendor:abbmodel:robotstudioscope:eqversion:5.61

Trust: 1.6

vendor:abbmodel:robotstudioscope:ltversion:5.6x

Trust: 0.8

vendor:abbmodel:robotstudioscope:eqversion:5.61.02

Trust: 0.8

vendor:abbmodel:robotstudioscope:eqversion:5.60-5.61.01.0

Trust: 0.6

vendor:abbmodel:test signalscope:eqversion:1.5

Trust: 0.6

vendor:abbmodel:robotstudioscope:eqversion:5.61.01.01

Trust: 0.3

vendor:abbmodel:test signal viewerscope:neversion:1.6

Trust: 0.3

vendor:abbmodel:robotstudioscope:neversion:5.61.2

Trust: 0.3

vendor:robotstudiomodel: - scope:eqversion:5.60

Trust: 0.2

vendor:robotstudiomodel: - scope:eqversion:5.61

Trust: 0.2

vendor:robotstudiomodel: - scope:eqversion:5.61.01

Trust: 0.2

vendor:test signal viewermodel: - scope:eqversion:1.5

Trust: 0.2

sources: IVD: ba9f79d4-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-08129 // BID: 70907 // JVNDB: JVNDB-2014-005292 // CNNVD: CNNVD-201411-106 // NVD: CVE-2014-5430

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-5430
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-5430
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-08129
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201411-106
value: MEDIUM

Trust: 0.6

IVD: ba9f79d4-2351-11e6-abef-000c29c66e3d
value: MEDIUM

Trust: 0.2

VULHUB: VHN-73371
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-5430
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-08129
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: ba9f79d4-2351-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-73371
severity: MEDIUM
baseScore: 6.9
vectorString: AV:L/AC:M/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.4
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: IVD: ba9f79d4-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-08129 // VULHUB: VHN-73371 // JVNDB: JVNDB-2014-005292 // CNNVD: CNNVD-201411-106 // NVD: CVE-2014-5430

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2014-005292 // NVD: CVE-2014-5430

THREAT TYPE

local

Trust: 0.9

sources: BID: 70907 // CNNVD: CNNVD-201411-106

TYPE

other

Trust: 0.8

sources: IVD: ba9f79d4-2351-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201411-106

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-005292

PATCH

title:RobotStudio download pageurl:http://new.abb.com/products/robotics/robotstudio/downloads

Trust: 0.8

title:Patch for multiple ABB product native code execution vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/51663

Trust: 0.6

sources: CNVD: CNVD-2014-08129 // JVNDB: JVNDB-2014-005292

EXTERNAL IDS

db:NVDid:CVE-2014-5430

Trust: 3.6

db:ICS CERTid:ICSA-14-308-01

Trust: 2.8

db:BIDid:70907

Trust: 1.0

db:CNVDid:CNVD-2014-08129

Trust: 0.8

db:CNNVDid:CNNVD-201411-106

Trust: 0.8

db:JVNDBid:JVNDB-2014-005292

Trust: 0.8

db:IVDid:BA9F79D4-2351-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:VULHUBid:VHN-73371

Trust: 0.1

sources: IVD: ba9f79d4-2351-11e6-abef-000c29c66e3d // CNVD: CNVD-2014-08129 // VULHUB: VHN-73371 // BID: 70907 // JVNDB: JVNDB-2014-005292 // CNNVD: CNNVD-201411-106 // NVD: CVE-2014-5430

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-14-308-01

Trust: 2.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-5430

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-5430

Trust: 0.8

url:http://www.securityfocus.com/bid/70907

Trust: 0.6

url:http://www.abb.com/

Trust: 0.3

url:http://www05.abb.com/global/scot/scot241.nsf/veritydisplay/77c96c7153b0622e83257d81004fa8d2/$file/si20022%20-%20advisory%20for%20abb%20robotstudio%20abb-vu-dmro-13944.pdf

Trust: 0.3

url:http://www05.abb.com/global/scot/scot241.nsf/veritydisplay/05d75a65f7103ef983257d81004cd6f5/$file/si20021-advisory%20abb%20test%20signal%20viewer-abb-vu-dmro-71374.pdf

Trust: 0.3

sources: CNVD: CNVD-2014-08129 // VULHUB: VHN-73371 // BID: 70907 // JVNDB: JVNDB-2014-005292 // CNNVD: CNNVD-201411-106 // NVD: CVE-2014-5430

CREDITS

Ivan Sanchezcode

Trust: 0.3

sources: BID: 70907

SOURCES

db:IVDid:ba9f79d4-2351-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2014-08129
db:VULHUBid:VHN-73371
db:BIDid:70907
db:JVNDBid:JVNDB-2014-005292
db:CNNVDid:CNNVD-201411-106
db:NVDid:CVE-2014-5430

LAST UPDATE DATE

2025-04-13T23:37:37.796000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-08129date:2014-11-07T00:00:00
db:VULHUBid:VHN-73371date:2014-11-07T00:00:00
db:BIDid:70907date:2014-10-29T00:00:00
db:JVNDBid:JVNDB-2014-005292date:2014-11-10T00:00:00
db:CNNVDid:CNNVD-201411-106date:2014-11-14T00:00:00
db:NVDid:CVE-2014-5430date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:IVDid:ba9f79d4-2351-11e6-abef-000c29c66e3ddate:2014-11-07T00:00:00
db:CNVDid:CNVD-2014-08129date:2014-11-07T00:00:00
db:VULHUBid:VHN-73371date:2014-11-07T00:00:00
db:BIDid:70907date:2014-10-29T00:00:00
db:JVNDBid:JVNDB-2014-005292date:2014-11-10T00:00:00
db:CNNVDid:CNNVD-201411-106date:2014-11-14T00:00:00
db:NVDid:CVE-2014-5430date:2014-11-07T11:55:03.767