CVE-2016-4524

MEDIUM

ABB PCM600 < 2.6 - Unauthenticated Sensitive Information Exposure via OPC Server Password Storage

Title source: llm
STIX 2.1

Description

ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-16-152-02

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 14.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-284 CWE-310
Status published
Products (1)
abb/pcm600 < 2.6
Published Jun 10, 2016
Tracked Since Feb 18, 2026