ID

VAR-201901-0482


CVE

CVE-2018-17928


TITLE

ABB CMS-770 Authentication Bypass Vulnerability

Trust: 0.8

sources: IVD: 5aa98943-b716-4a6c-853e-43811d90a1fa // CNVD: CNVD-2019-19835

DESCRIPTION

The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing the user authentication mechanism. CMS-770 Contains an authentication vulnerability.Information may be obtained. The CMS-770 is a multi-loop monitoring system from ABB for monitoring the branch circuit of electrical systems. An authentication bypass vulnerability exists in ABB CMS-770 1.7.1 and earlier. ABB CMS-770 is prone to an authentication-bypass vulnerability. ABB CMS-770 versions 1.7.1 and prior are vulnerable

Trust: 2.7

sources: NVD: CVE-2018-17928 // JVNDB: JVNDB-2018-014211 // CNVD: CNVD-2019-19835 // BID: 106244 // IVD: 5aa98943-b716-4a6c-853e-43811d90a1fa // VULHUB: VHN-128436

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 5aa98943-b716-4a6c-853e-43811d90a1fa // CNVD: CNVD-2019-19835

AFFECTED PRODUCTS

vendor:abbmodel:cms-770scope:lteversion:1.7.1

Trust: 1.8

vendor:abbmodel:cms-770scope:lteversion:<=1.7.1

Trust: 0.6

vendor:vmwaremodel:cms-770scope:eqversion:1.7.1

Trust: 0.3

vendor:cms 770model: - scope:eqversion:*

Trust: 0.2

sources: IVD: 5aa98943-b716-4a6c-853e-43811d90a1fa // CNVD: CNVD-2019-19835 // BID: 106244 // JVNDB: JVNDB-2018-014211 // NVD: CVE-2018-17928

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-17928
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-17928
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2019-19835
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201812-785
value: MEDIUM

Trust: 0.6

IVD: 5aa98943-b716-4a6c-853e-43811d90a1fa
value: MEDIUM

Trust: 0.2

VULHUB: VHN-128436
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2018-17928
severity: LOW
baseScore: 3.3
vectorString: AV:A/AC:L/AU:N/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2019-19835
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 5aa98943-b716-4a6c-853e-43811d90a1fa
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-128436
severity: LOW
baseScore: 3.3
vectorString: AV:A/AC:L/AU:N/C:P/I:N/A:N
accessVector: ADJACENT_NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 6.5
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-17928
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: IVD: 5aa98943-b716-4a6c-853e-43811d90a1fa // CNVD: CNVD-2019-19835 // VULHUB: VHN-128436 // JVNDB: JVNDB-2018-014211 // CNNVD: CNNVD-201812-785 // NVD: CVE-2018-17928

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.9

sources: VULHUB: VHN-128436 // JVNDB: JVNDB-2018-014211 // NVD: CVE-2018-17928

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-201812-785

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-201812-785

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-014211

PATCH

title:トップページurl:https://new.abb.com/jp

Trust: 0.8

title:ABB CMS-770 authentication bypass vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/165661

Trust: 0.6

title:ABB CMS-770 Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=87983

Trust: 0.6

sources: CNVD: CNVD-2019-19835 // JVNDB: JVNDB-2018-014211 // CNNVD: CNNVD-201812-785

EXTERNAL IDS

db:NVDid:CVE-2018-17928

Trust: 3.6

db:ICS CERTid:ICSA-18-352-06

Trust: 3.4

db:BIDid:106244

Trust: 2.0

db:CNNVDid:CNNVD-201812-785

Trust: 0.9

db:CNVDid:CNVD-2019-19835

Trust: 0.8

db:JVNDBid:JVNDB-2018-014211

Trust: 0.8

db:IVDid:5AA98943-B716-4A6C-853E-43811D90A1FA

Trust: 0.2

db:SEEBUGid:SSVID-98834

Trust: 0.1

db:VULHUBid:VHN-128436

Trust: 0.1

sources: IVD: 5aa98943-b716-4a6c-853e-43811d90a1fa // CNVD: CNVD-2019-19835 // VULHUB: VHN-128436 // BID: 106244 // JVNDB: JVNDB-2018-014211 // CNNVD: CNNVD-201812-785 // NVD: CVE-2018-17928

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-18-352-06

Trust: 3.4

url:http://www.securityfocus.com/bid/106244

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-17928

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-17928

Trust: 0.8

url:http://www.abb.com/

Trust: 0.3

url:http://search-ext.abb.com/library/download.aspx?documentid=abbvu-epbp-r-5673&languagecode=en&documentpartid=2cka008100a0351%3b%202cca688307r0001&action=launch

Trust: 0.3

sources: CNVD: CNVD-2019-19835 // VULHUB: VHN-128436 // BID: 106244 // JVNDB: JVNDB-2018-014211 // CNNVD: CNNVD-201812-785 // NVD: CVE-2018-17928

CREDITS

Maxim Rupp (RuppIT)

Trust: 0.3

sources: BID: 106244

SOURCES

db:IVDid:5aa98943-b716-4a6c-853e-43811d90a1fa
db:CNVDid:CNVD-2019-19835
db:VULHUBid:VHN-128436
db:BIDid:106244
db:JVNDBid:JVNDB-2018-014211
db:CNNVDid:CNNVD-201812-785
db:NVDid:CVE-2018-17928

LAST UPDATE DATE

2024-11-23T22:51:53.046000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-19835date:2019-06-30T00:00:00
db:VULHUBid:VHN-128436date:2019-10-09T00:00:00
db:BIDid:106244date:2018-12-19T00:00:00
db:JVNDBid:JVNDB-2018-014211date:2019-03-14T00:00:00
db:CNNVDid:CNNVD-201812-785date:2019-10-17T00:00:00
db:NVDid:CVE-2018-17928date:2024-11-21T03:55:13.640

SOURCES RELEASE DATE

db:IVDid:5aa98943-b716-4a6c-853e-43811d90a1fadate:2019-06-30T00:00:00
db:CNVDid:CNVD-2019-19835date:2019-06-28T00:00:00
db:VULHUBid:VHN-128436date:2019-01-31T00:00:00
db:BIDid:106244date:2018-12-19T00:00:00
db:JVNDBid:JVNDB-2018-014211date:2019-03-14T00:00:00
db:CNNVDid:CNNVD-201812-785date:2018-12-19T00:00:00
db:NVDid:CVE-2018-17928date:2019-01-31T21:29:00.223