Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-10287

Опубликовано: 15 июл. 2020
Источник: nvd
CVSS3: 9.1
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of our research, we found multiple production systems running these exact default credentials and consider thereby this an exposure that should be mitigated. Moreover, future deployments should consider that these defaults should be forbidden (user should be forced to change them).

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:abb:irb140_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:irb140:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:abb:irc5_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:irc5:-:*:*:*:*:*:*:*

EPSS

Процентиль: 59%
0.00384
Низкий

9.1 Critical

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-255
CWE-522

Связанные уязвимости

github
больше 3 лет назад

The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well documented functionality that helps customer set up however, out of our research, we found multiple production systems running these exact default credentials and consider thereby this an exposure that should be mitigated. Moreover, future deployments should consider that these defaults should be forbidden (user should be forced to change them).

EPSS

Процентиль: 59%
0.00384
Низкий

9.1 Critical

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-255
CWE-522