QID 590733
Date Published: 2022-03-15
QID 590733: ABB Automation Builder 2.2 and Prior and Drive Application Builder 1.0 Vulnerability (ABBVU-MODR-3ADR010465)
Affected Products
The following products are affected by this vulnerability:
All Automation Builder versions prior V2.3.0
(only when using for programming AC500 V3 PLC or IEC61131 programmable Drives)
Drive Application Builder V1.0.0
This applies to both the 32-bit and 64-bit variants.
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
An attacker who successfully exploited this vulnerability could insert and run arbitrary JavaScript and/or ActiveX code in an affected system.
Solution
Customers are advised to refer to CERT MITIGATIONS section ABBVU-MODR-3ADR010465 for affected packages and patching details.
Vendor References
CVEs related to QID 590733
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ABBVU-MODR-3ADR010465 |
|