ID

VAR-202112-0667


CVE

CVE-2021-22279


TITLE

OmniCore  for robot controller  RobotWare  Vulnerability regarding lack of authentication for critical features in

Trust: 0.8

sources: JVNDB: JVNDB-2021-016331

DESCRIPTION

A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port. OmniCore for robot controller RobotWare There is a vulnerability in the lack of authentication for critical features.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2021-22279 // JVNDB: JVNDB-2021-016331

IOT TAXONOMY

category:['industrial device']sub_category:robot

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:abbmodel:omnicore c30scope:ltversion:7.3.2

Trust: 1.0

vendor:abbmodel:omnicore c30scope:eqversion: -

Trust: 0.8

vendor:abbmodel:omnicore c30scope: - version: -

Trust: 0.8

vendor:abbmodel:omnicore c30scope:eqversion:omnicore c30 firmware

Trust: 0.8

sources: JVNDB: JVNDB-2021-016331 // NVD: CVE-2021-22279

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-22279
value: CRITICAL

Trust: 1.0

cybersecurity@ch.abb.com: CVE-2021-22279
value: CRITICAL

Trust: 1.0

NVD: CVE-2021-22279
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-202112-1044
value: CRITICAL

Trust: 0.6

nvd@nist.gov: CVE-2021-22279
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2021-22279
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 2.0

OTHER: JVNDB-2021-016331
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2021-016331 // CNNVD: CNNVD-202112-1044 // NVD: CVE-2021-22279 // NVD: CVE-2021-22279

PROBLEMTYPE DATA

problemtype:CWE-306

Trust: 1.0

problemtype:Lack of authentication for critical features (CWE-306) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-016331 // NVD: CVE-2021-22279

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202112-1044

TYPE

access control error

Trust: 0.6

sources: CNNVD: CNNVD-202112-1044

PATCH

title:SI20265url:https://search.abb.com/library/Download.aspx?DocumentID=SI20265&LanguageCode=en&DocumentPartId=&Action=Launch

Trust: 0.8

title:OmniCore robot Fixes for access control error vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=174649

Trust: 0.6

sources: JVNDB: JVNDB-2021-016331 // CNNVD: CNNVD-202112-1044

EXTERNAL IDS

db:NVDid:CVE-2021-22279

Trust: 3.3

db:JVNDBid:JVNDB-2021-016331

Trust: 0.8

db:CNNVDid:CNNVD-202112-1044

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2021-016331 // CNNVD: CNNVD-202112-1044 // NVD: CVE-2021-22279

REFERENCES

url:https://search.abb.com/library/download.aspx?documentid=si20265&languagecode=en&documentpartid=&action=launch

Trust: 1.6

url:https://nvd.nist.gov/vuln/detail/cve-2021-22279

Trust: 1.4

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // JVNDB: JVNDB-2021-016331 // CNNVD: CNNVD-202112-1044 // NVD: CVE-2021-22279

SOURCES

db:OTHERid: -
db:JVNDBid:JVNDB-2021-016331
db:CNNVDid:CNNVD-202112-1044
db:NVDid:CVE-2021-22279

LAST UPDATE DATE

2025-01-30T21:21:00.776000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2021-016331date:2022-12-12T04:52:00
db:CNNVDid:CNNVD-202112-1044date:2021-12-20T00:00:00
db:NVDid:CVE-2021-22279date:2021-12-17T01:41:46.123

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2021-016331date:2022-12-12T00:00:00
db:CNNVDid:CNNVD-202112-1044date:2021-12-13T00:00:00
db:NVDid:CVE-2021-22279date:2021-12-13T16:15:08.590