QID 590998

Date Published: 2022-08-24

QID 590998: ABB UPS Adapter CS141 Vulnerability (ABBVU-ELSP-4178-2150)

AFFECTED PRODUCTS
The vulnerability affects the products listed below. Affected firmware versions are 1.66 - 1.88.
4NWP102879R0001 CS141 Advanced - Box
4NWP102880R0001 CS141 Advanced - Slot
4NWP102881R0001 CS141 ModBus - Box
4NWP102882R0001 CS141 ModBus - Slot
4NWP102687R0001 CS141 Basic - Box
4NWP102688R0001 CS141 Basic - Slot

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

An attacker who successfully exploited this vulnerability could read arbitrary files and directories from the UPS Adapter CS141

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ABBVU-ELSP-4178-2150 for affected packages and patching details.

    CVEs related to QID 590998

    Software Advisories
    Advisory ID Software Component Link
    ABBVU-ELSP-4178-2150 URL Logo library.e.abb.com/public/ee46f3ff5823400f991ebd9bd43a297e/2CMT2020-005913%20Security%20Advisory%20CS141.pdf