CVE-2019-18250

In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device.
References
Link Resource
https://www.us-cert.gov/ics/advisories/icsa-19-318-05 Not Applicable Permissions Required Third Party Advisory US Government Resource
https://iotsecuritynews.com/abb-power-generation-information-manager-pgim-and-plant-connect/ Third Party Advisory
https://www.us-cert.gov/ics/advisories/icsa-19-318-05 Not Applicable Permissions Required Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:abb:plant_connect:*:*:*:*:*:*:*:*
cpe:2.3:a:abb:power_generation_information_manager:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:32

Type Values Removed Values Added
References () https://www.us-cert.gov/ics/advisories/icsa-19-318-05 - Not Applicable, Permissions Required, Third Party Advisory, US Government Resource () https://www.us-cert.gov/ics/advisories/icsa-19-318-05 - Not Applicable, Permissions Required, Third Party Advisory, US Government Resource

Information

Published : 2019-11-26 00:15

Updated : 2024-11-21 04:32


NVD link : CVE-2019-18250

Mitre link : CVE-2019-18250

CVE.ORG link : CVE-2019-18250


JSON object : View

Products Affected

abb

  • power_generation_information_manager
  • plant_connect
CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel

CWE-287

Improper Authentication