{"api_version":"1","generated_at":"2026-07-24T19:52:33+00:00","cve":"CVE-2019-18250","urls":{"html":"https://cve.report/CVE-2019-18250","api":"https://cve.report/api/cve/CVE-2019-18250.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-18250","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-18250"},"summary":{"title":"CVE-2019-18250","description":"In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device.","state":"PUBLIC","assigner":"ics-cert@hq.dhs.gov","published_at":"2019-11-26 00:15:00","updated_at":"2021-10-29 19:11:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://iotsecuritynews.com/abb-power-generation-information-manager-pgim-and-plant-connect/","name":"https://iotsecuritynews.com/abb-power-generation-information-manager-pgim-and-plant-connect/","refsource":"MISC","tags":["Third Party Advisory"],"title":"ABB Power Generation Information Manager (PGIM) and Plant Connect - IoT Security News","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.us-cert.gov/ics/advisories/icsa-19-318-05","name":"https://www.us-cert.gov/ics/advisories/icsa-19-318-05","refsource":"MISC","tags":["Not Applicable","Permissions Required"],"title":"ABB Power Generation Information Manager (PGIM) and Plant Connect | CISA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-18250","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-18250","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"18250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"abb","cpe5":"plant_connect","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"18250","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"abb","cpe5":"plant_connect","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"18250","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"abb","cpe5":"power_generation_information_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"18250","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"abb","cpe5":"power_generation_information_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-18250","ASSIGNER":"ics-cert@hq.dhs.gov","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"ABB Power Generation Information Manager (PGIM) and Plant Connect All Versions","version":{"version_data":[{"version_value":"ABB Power Generation Information Manager (PGIM) and Plant Connect All Versions"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"AUTHENTICATION BYPASS USING AN ALTERNATE PATH OR CHANNEL CWE-288"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://www.us-cert.gov/ics/advisories/icsa-19-318-05","url":"https://www.us-cert.gov/ics/advisories/icsa-19-318-05"}]},"description":{"description_data":[{"lang":"eng","value":"In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device."}]}},"nvd":{"publishedDate":"2019-11-26 00:15:00","lastModifiedDate":"2021-10-29 19:11:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:abb:plant_connect:*:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:abb:power_generation_information_manager:*:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"18250","Ordinal":"158624","Title":"CVE-2019-18250","CVE":"CVE-2019-18250","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"18250","Ordinal":"1","NoteData":"In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"18250","Ordinal":"2","NoteData":"2019-11-25","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"18250","Ordinal":"3","NoteData":"2019-11-25","Type":"Other","Title":"Modified"}]}}}