CVE-2018-18995
Summary
| CVE | CVE-2018-18995 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-03 22:29:00 UTC |
| Updated | 2019-10-09 23:37:00 UTC |
| Description | Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, including conducting device resets, reading or modifying registers, and changing configuration settings such as IP addresses. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| ABB GATE-E2 | CISA |
MISC |
ics-cert.us-cert.gov |
Mitigation, Third Party Advisory, US Government Resource |
| ABB GATE-E2 ICSA-18-352-01 Authentication Bypass and Cross-site Scripting Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590505 ABB GATE-E2 Multiple Vulnerabilities (ICSA-18-352-01)