CVE-2021-22276
23.09.2021, 17:15
The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.Enginsight
Vendor | Product | Version |
---|---|---|
abb | system_access_point_2.0_firmware | 𝑥 < 2.6.4 |
abb | system_access_point_127v_firmware | 𝑥 < 2.6.4 |
abb | wl-system_access_point_127v_firmware | 𝑥 < 2.6.4 |
abb | wl-system_access_point_firmware | 𝑥 < 2.6.4 |
abb | wl-system_access_point_2.0_firmware | 𝑥 < 2.6.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-354 - Improper Validation of Integrity Check ValueThe software does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.