CVE-2022-0010
Severity CVSS v4.0:
Pending analysis
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
22/05/2023
Last modified:
01/06/2023
Description
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools.<br />
<br />
<br />
An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to exploit this vulnerability to gain control of system nodes. <br />
<br />
This issue affects QCS 800xA: from 1.0;0 through 6.1SP2; QCS AC450: from 1.0;0 through 5.1SP2; Platform Engineering Tools: from 1.0:0 through 2.3.0.<br />
<br />
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:abb:platform_engineering_tools:*:*:*:*:*:*:*:* | 1.0.0 (including) | 2.3.0 (including) |
cpe:2.3:o:abb:qcs_800xa_firmware:*:*:*:*:*:*:*:* | 1.0.0 (including) | 5.1.0 (including) |
cpe:2.3:o:abb:qcs_800xa_firmware:5.1.0:sp2:*:*:*:*:*:* | ||
cpe:2.3:h:abb:qcs_800xa:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:abb:qcs_ac450_firmware:*:*:*:*:*:*:*:* | 1.0.0 (including) | 6.1.0 (including) |
cpe:2.3:o:abb:qcs_ac450_firmware:6.1.0:sp2:*:*:*:*:*:* | ||
cpe:2.3:h:abb:qcs_ac450:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page