You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
id: 3326title: 'RVD#3326: Hardcoded default credentials on IRC 5 OPC Server'type: exposuredescription: The IRC5 family with UAS service enabled comes by default with credentialsthat can be found on publicly available manuals. ABB considers this a well documentedfunctionality that helps customer set up however, out of our research, we foundmultiple production systems running these exact default credentials and considerthereby this an exposure that should be mitigated. Moreover, future deploymentsshould consider that these defaults should be forbidden (user should be forced tochange them).cwe: CWE-255cve: CVE-2020-10287keywords:
- IRC5, FTP, Credentialssystem: IRB140, IRC5,vendor: ABBseverity:
rvss-score: 10.0rvss-vector: RVSS:1.0/AV:RN/AC:L/PR:N/UI:N/Y:M/S:U/C:H/I:N/A:H/H:U/severity-description: Criticalcvss-score: 9.1cvss-vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:Hlinks:
- https://nvd.nist.gov/vuln/detail/CVE-2010-2966
- https://github.com/aliasrobotics/RVD/issues/3326flaw:
phase: testingspecificity: general-issuearchitectural-location: Platform codeapplication: OPC Serversubsystem: UI:Loginpackage: N/Alanguages: Nonedate-detected: 2020-05-18detected-by: Alfonso Glera, Victor Mayoral Vilches (Alias Robotics)detected-by-method: testing dynamic, Browser.date-reported: '2020-07-15'reported-by: Victor Mayoral Vilchesreported-by-relationship: security researcherissue: https://github.com/aliasrobotics/RVD/issues/3326reproducibility: Alwaystrace: Not disclosedreproduction: Not disclosedreproduction-image: Not disclosedexploitation:
description: Not disclosedexploitation-image: Not disclosedexploitation-vector: Not disclosedexploitation-recipe: ''mitigation:
description: Not disclosedpull-request: Not discloseddate-mitigation: null
The text was updated successfully, but these errors were encountered:
The text was updated successfully, but these errors were encountered: