CVE-2019-7225

Summary

CVECVE-2019-7225
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2019-06-27 17:15:00 UTC
Updated2023-05-16 11:15:00 UTC
DescriptionThe ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. These credentials are the idal123 password for the IdalMaster account, and the exor password for the exor account. These credentials are used over both HTTP(S) and FTP. There is no option to disable or change these undocumented credentials. An attacker can use these credentials to login to ABB HMI to read/write HMI configuration files and also to reset the device. This affects ABB CP635 HMI, CP600 HMIClient, Panel Builder 600, IDAL FTP server, IDAL HTTP server, and multiple other HMI components.

Risk And Classification

Problem Types: CWE-798

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Abb Cp620 - All All All
Hardware Abb Cp620 - All All All
Hardware Abb Cp620-web - All All All
Hardware Abb Cp620-web - All All All
Operating System Abb Cp620-web Firmware All All All All
Operating System Abb Cp620 Firmware All All All All
Hardware Abb Cp630 - All All All
Hardware Abb Cp630 - All All All
Hardware Abb Cp630-web - All All All
Hardware Abb Cp630-web - All All All
Operating System Abb Cp630-web Firmware All All All All
Operating System Abb Cp630 Firmware All All All All
Hardware Abb Cp635 - All All All
Hardware Abb Cp635 - All All All
Hardware Abb Cp635-b - All All All
Hardware Abb Cp635-b - All All All
Operating System Abb Cp635-b Firmware All All All All
Hardware Abb Cp635-web - All All All
Hardware Abb Cp635-web - All All All
Operating System Abb Cp635-web Firmware All All All All
Operating System Abb Cp635 Firmware All All All All
Hardware Abb Cp651 - All All All
Hardware Abb Cp651 - All All All
Hardware Abb Cp651-web - All All All
Hardware Abb Cp651-web - All All All
Operating System Abb Cp651-web Firmware All All All All
Operating System Abb Cp651 Firmware All All All All
Hardware Abb Cp661 - All All All
Hardware Abb Cp661 - All All All
Hardware Abb Cp661-web - All All All
Hardware Abb Cp661-web - All All All
Operating System Abb Cp661-web Firmware All All All All
Operating System Abb Cp661 Firmware All All All All
Hardware Abb Cp665 - All All All
Hardware Abb Cp665 - All All All
Hardware Abb Cp665-web - All All All
Hardware Abb Cp665-web - All All All
Operating System Abb Cp665-web Firmware All All All All
Operating System Abb Cp665 Firmware All All All All
Hardware Abb Cp676 - All All All
Hardware Abb Cp676 - All All All
Hardware Abb Cp676-web - All All All
Hardware Abb Cp676-web - All All All
Operating System Abb Cp676-web Firmware All All All All
Operating System Abb Cp676 Firmware All All All All
Hardware Abb Pb610 - All All All
Hardware Abb Pb610 - All All All
Operating System Abb Pb610 Firmware All All All All

References

ReferenceSourceLinkTags
404 Not Found MISC www.darkmatter.ae Exploit, Patch, Third Party Advisory
ABB HMI Hardcoded Credentials ≈ Packet Storm MISC packetstormsecurity.com Third Party Advisory, VDB Entry
Multiple ABB Products CVE-2019-7225 Hardcoded Credentials Vulnerability BID www.securityfocus.com Third Party Advisory, VDB Entry
Full Disclosure: XL-19-009 - ABB HMI Hardcoded Credentials Vulnerability FULLDISC seclists.org Mailing List, Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 591299 ABB CP620, CP630, CP635 Hardcoded Credentials Multiple Vulnerabilities (3ADR010376)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report