CVE-2018-18995

CRITICAL

ABB GATE-E1 and GATE-E2 Firmware - Missing Authentication for Critical Function

Title source: llm
STIX 2.1

Description

Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, including conducting device resets, reading or modifying registers, and changing configuration settings such as IP addresses.

References (2)

Core 2
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-18-352-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106247

Scores

CVSS v3 9.8
EPSS 0.0132
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (2)
abb/gate-e1_firmware
abb/gate-e2_firmware
Published Jan 03, 2019
Tracked Since Feb 18, 2026