CVE-2021-22278

A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ABBCNA
6.7 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
Affected Products (NVD)
VendorProductVersion
abbupdate_manager
2.1
abbupdate_manager
2.1.0.4
abbupdate_manager
2.2
abbupdate_manager
2.2.0.1
abbupdate_manager
2.2.0.2
abbupdate_manager
2.2.0.23
abbupdate_manager
2.3.0.60
abbupdate_manager
2.4.20041.1
abbupdate_manager
2.4.20119.2
abbupdate_manager
2.7 ≤
𝑥
≤ 2.10
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
abbpcm600
2.7
CNA
abbpcm600
𝑥
≤ 2.10
CNA
abbpcm600
2.1
CNA
abbpcm600
2.1.0.4
CNA
abbpcm600
2.2
CNA
abbpcm600
2.2.0.1
CNA
abbpcm600
2.2.0.2
CNA
abbpcm600
2.2.0.23
CNA
abbpcm600
2.3.0.60
CNA
abbpcm600
2.4.20041.1
CNA
abbpcm600
2.4.20119.2
CNA