CVE-2019-7225

The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. These credentials are the idal123 password for the IdalMaster account, and the exor password for the exor account. These credentials are used over both HTTP(S) and FTP. There is no option to disable or change these undocumented credentials. An attacker can use these credentials to login to ABB HMI to read/write HMI configuration files and also to reset the device. This affects ABB CP635 HMI, CP600 HMIClient, Panel Builder 600, IDAL FTP server, IDAL HTTP server, and multiple other HMI components.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:abb:cp620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp620:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:abb:cp620-web_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp620-web:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:abb:cp630_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp630:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:abb:cp630-web_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp630-web:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:abb:cp635_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp635:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:abb:cp635-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp635-b:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:abb:cp635-web_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp635-web:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:abb:pb610_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:pb610:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:abb:cp651-web_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp651-web:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:abb:cp661_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp661:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:abb:cp661-web_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp661-web:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:abb:cp665_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp665:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:abb:cp665-web_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp665-web:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:abb:cp676_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp676:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:abb:cp676-web_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp676-web:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:abb:cp651_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:cp651:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:47

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/153397/ABB-HMI-Hardcoded-Credentials.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/153397/ABB-HMI-Hardcoded-Credentials.html - Third Party Advisory, VDB Entry
References () http://seclists.org/fulldisclosure/2019/Jun/38 - Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2019/Jun/38 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/108922 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/108922 - Third Party Advisory, VDB Entry
References () https://www.darkmatter.ae/xen1thlabs/abb-hmi-hardcoded-credentials-vulnerability-xl-19-009/ - Exploit, Patch, Third Party Advisory () https://www.darkmatter.ae/xen1thlabs/abb-hmi-hardcoded-credentials-vulnerability-xl-19-009/ - Exploit, Patch, Third Party Advisory

Information

Published : 2019-06-27 17:15

Updated : 2024-11-21 04:47


NVD link : CVE-2019-7225

Mitre link : CVE-2019-7225

CVE.ORG link : CVE-2019-7225


JSON object : View

Products Affected

abb

  • cp620-web
  • cp635-b_firmware
  • cp661
  • cp676-web_firmware
  • cp676-web
  • cp661_firmware
  • cp630-web_firmware
  • cp635
  • cp620
  • cp635-web
  • cp620_firmware
  • cp651-web_firmware
  • cp665-web
  • cp651-web
  • cp676
  • cp620-web_firmware
  • cp665_firmware
  • cp630
  • cp676_firmware
  • cp651_firmware
  • cp630-web
  • cp661-web
  • cp661-web_firmware
  • cp630_firmware
  • cp635-web_firmware
  • cp665
  • pb610
  • cp651
  • cp635_firmware
  • cp635-b
  • pb610_firmware
  • cp665-web_firmware
CWE
CWE-798

Use of Hard-coded Credentials