CVE-2019-18250

In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device.
References
Link Resource
https://iotsecuritynews.com/abb-power-generation-information-manager-pgim-and-plant-connect/ Third Party Advisory
https://www.us-cert.gov/ics/advisories/icsa-19-318-05 Not Applicable Permissions Required Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:abb:plant_connect:*:*:*:*:*:*:*:*
cpe:2.3:a:abb:power_generation_information_manager:*:*:*:*:*:*:*:*

History

29 Oct 2021, 19:11

Type Values Removed Values Added
References (MISC) https://www.us-cert.gov/ics/advisories/icsa-19-318-05 - Not Applicable, Permissions Required (MISC) https://www.us-cert.gov/ics/advisories/icsa-19-318-05 - Not Applicable, Permissions Required, Third Party Advisory, US Government Resource
CWE CWE-522 CWE-287

Information

Published : 2019-11-26 00:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-18250

Mitre link : CVE-2019-18250

CVE.ORG link : CVE-2019-18250


JSON object : View

Products Affected

abb

  • plant_connect
  • power_generation_information_manager
CWE
CWE-287

Improper Authentication

CWE-288

Authentication Bypass Using an Alternate Path or Channel