ABB CMS-770
ABB CMS-770 Condition Monitoring System (version 1.7.1 and earlier) contains an authentication bypass vulnerability (CWE-287) that allows an attacker on the network to bypass login requirements and gain full control of the device. The vulnerability has a CVSS score of 8.8, indicating high impact on confidentiality, integrity, and availability. No patch is available from ABB. The device must be installed according to ABB's updated technical manual, and network isolation is the primary mitigation strategy.
- Network access to the CMS-770 on the same segment or routed path (Layer 2 or Layer 3)
- No credentials required to exploit the authentication bypass
- Device running CMS-770 firmware version 1.7.1 or earlier
Patching may require device reboot — plan for process interruption
/api/v1/advisories/e62369e1-2d99-416b-ba0f-fcd7e225724cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.