ABB has an update available to mitigate a use of hard-coded credentials vulnerability in its CP651 HMI, according to a report with NCCIC.
Successful exploitation of this vulnerability, which is exploitable from an adjacent network, could allow an attacker to prevent legitimate access to an affected system node, remotely cause an affected system node to stop, take control of an affected system node, or insert and run arbitrary code in an affected system node. ABB self-reported the vulnerability.
RELATED STORIES
ABB Clears Panel Builder 600 Holes
Medtronic Plan for Insulin Pump Hole
Phoenix Contact Working on Software Suite Fix
BD Alaris Fixes Gateway Workstation
ABB reports the vulnerability affects the following CP651 HMI products:
• CP651, order code: 1SAP551100R0001, revision index B1 with BSP UN30 v1.76 and prior
• CP651-WEB, order code: 1SAP551200R0001, revision index A0 with BSP UN30 v1.76 and prior
• CP661, order code: 1SAP561100R0001, revision index B1 with BSP UN30 v1.76 and prior
• CP661-WEB, order code: 1SAP561200R0001, revision index A0 with BSP UN30 v1.76 and prior
• CP665, order code: 1SAP565100R0001, revision index B1 with BSP UN30 v1.76 and prior
• CP665-WEB, order code: 1SAP565200R0001, revision index A0 with BSP UN30 v1.76 and prior
• CP676, order code: 1SAP576100R0001, revision index B1 with BSP UN30 v1.76 and prior
• CP676-WEB, order code: 1SAP576200R0001, revision index A0 with BSP UN30 v1.76 and prior
In the vulnerability, the ABB CP651 HMI component implements hidden administrative accounts used during the provisioning phase of the HMI interface.
CVE-2019-10995 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 8.8.
The product sees use mainly in the critical manufacturing sector. It also sees action on a global basis.
No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage the issue.
ABB recommends users apply the BSP update on affected CP600 control panels at their earliest convenience.
• New version of PB610 Panel Builder 600 v2.8.0.424, which is provided via Automation Builder 2.2 SP2
• New version of BSP (board support package) UN30 v2.31
Click here to see ABB cybersecurity advisory document number 3ADR010402 for more information about this vulnerability and two other security issues and their mitigations.

