ABB RMC-100
cpe:2.3:h:abb:rmc-100:*:*:*:*:*:*:*, +1 more
- >= 2105457-043, <= 2105457-045
A vulnerability exists in ABB RMC-100 and RMC-100 LITE devices due to the use of hard-coded cryptographic keys. When the REST interface is enabled by the user, an attacker with access to the source code and control network can bypass authentication and access MQTT configuration data. This vulnerability affects RMC-100 versions 2105457-043 through 2105457-045 and RMC-100 LITE versions 2106229-015 through 2106229-016.
Exploitation of this vulnerability allows for authentication bypass on the REST interface, enabling unauthorized access to MQTT configuration data.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.