QID 591388

Date Published: 2023-04-03

QID 591388: ABB AFx series Secure Sockets Layer (SSL) 3.0 Protocol and POODLE Attack Vulnerability (ABB-VU-PSAC- 1KHW028569)

AFFECTED PRODUCTS
AFS650/AFS655/AFS670/AFS675/AFS677/AFR677: version 08.0.05 and prior.
AFS660/AFS665: version 03.0.02 and prior.

QID Detection Logic:
This QID checks for the Vulnerable version of ABB AFx series using passive scanning.

An attacker who successfully exploits this vulnerability could get hold of the user credentials and cryptographic keys used to login to the device.

  • CVSS V3 rated as Medium - 3.4 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ABB-VU-PSAC- 1KHW028569 for affected packages and patching details.

    CVEs related to QID 591388

    Software Advisories
    Advisory ID Software Component Link