CVE-2018-18995 Vulnerability Details

  /     /     /  

CVE-2018-18995 Metadata Quick Info

CVE Published: 03/01/2019 | CVE Updated: 05/08/2024 | CVE Year: 2018
Source: icscert | Vendor: n/a | Product: ABB GATE-E1 and GATE-E2
Status : PUBLISHED

CVE-2018-18995 Description

Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, including conducting device resets, reading or modifying registers, and changing configuration settings such as IP addresses.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-306
CWE Name: Missing Authentication for Critical Function CWE-306
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).