Unauthorized Modifications of Firmware and Configuration
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.6epss 0.1%
exploitation probability
0.1%top 95% of all CVEs
observed exploitation
nono source reports it
ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configuration to the system node, causing the node to stop, become inaccessible, or allowing the attacker to take control of the node.
CVSS:4.0/AV:A/AC:H/AT:P/PR:H/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/S:P/AU:N/R:I/V:D/RE:H/U:Amber
Affected products
ABB · 620 Series IEC/CNABB · ARG600/ARP600/ARR600/ARC600 single SIMABB · ARG600/ARP600 dual SIMABB · ARM600ABB · COM600ABB · COM600F ANSIABB · RBX615ABB · RE_630ABB · REC601/RER601ABB · REC603/RER603ABB · REF542plusABB · Relion Protection Relays 615 series ANSIABB · Relion Protection Relays 615 series CNABB · Relion Protection Relays 615 series IECABB · Relion Protection Relays RE_611 IECABB · Relion Protection Relays REC615ABB · Relion Protection Relays RED615 IECABB · Relion Protection Relays REF615 ANSIABB · Relion Protection Relays REF615 IECABB · Relion Protection Relays REF615R ANSIABB · Relion Protection Relays RER615ABB · Relion Protection Relays REX610ABB · Relion Protection Relays REX615ABB · Relion Protection Relays REX640ABB · RER620 ANSIABB · RIO600ABB · Smart Substation Control and Protection SSC600ABB · SPA ZC-400ABB · SPA ZC-402ABB · Substation Merging Unit SMU615ABB · SUE 3000