CVE-2022-1596

Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:abb:rex640_pcl1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl1:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:abb:rex640_pcl2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl2:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:abb:rex640_pcl3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl3:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:41

Type Values Removed Values Added
References () https://search.abb.com/library/Download.aspx?DocumentID=2NGA001421 - Mitigation, Vendor Advisory () https://search.abb.com/library/Download.aspx?DocumentID=2NGA001421 - Mitigation, Vendor Advisory

29 Jun 2022, 14:27

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 6.5
CPE cpe:2.3:o:abb:rex640_pcl1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl3:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl2:-:*:*:*:*:*:*:*
cpe:2.3:o:abb:rex640_pcl3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:rex640_pcl2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:rex640_pcl1:-:*:*:*:*:*:*:*
CWE CWE-732
References (MISC) https://search.abb.com/library/Download.aspx?DocumentID=2NGA001421 - (MISC) https://search.abb.com/library/Download.aspx?DocumentID=2NGA001421 - Mitigation, Vendor Advisory

21 Jun 2022, 15:34

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-21 15:15

Updated : 2024-11-21 06:41


NVD link : CVE-2022-1596

Mitre link : CVE-2022-1596

CVE.ORG link : CVE-2022-1596


JSON object : View

Products Affected

abb

  • rex640_pcl3
  • rex640_pcl1_firmware
  • rex640_pcl2_firmware
  • rex640_pcl3_firmware
  • rex640_pcl2
  • rex640_pcl1
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource