PT-2022-6499 · Abb · Abb Rccmd

CVE-2022-4126

·

Published

2022-11-23

·

Updated

2023-07-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ABB RCCMD versions prior to 4.40 230207
Description The issue is related to the use of default passwords in the ABB RCCMD client-server application for managing uninterruptible power supplies. This could allow a remote attacker to execute arbitrary code or gain full control over the application by trying common or default usernames and passwords.
Recommendations For versions prior to 4.40 230207, update to version 4.40 230207 or later to resolve the issue. As a temporary workaround, consider changing the default passwords to unique, strong passwords until a patch is applied. Restrict access to the application to minimize the risk of exploitation.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01779
CVE-2022-4126

Affected Products

Abb Rccmd