CVE-2018-18995
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, including conducting device resets,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, including conducting device resets, reading or modifying registers, and changing configuration settings such as IP addresses.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.65% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- abb/gate-e1 firmware · abb/gate-e2 firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/106247Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-352-01Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/106247Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-352-01Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.