ABB CP635 HMI
ABB CP600 control panels (CP620, CP630, CP635 series) running board support package (BSP) UN31 v1.76 and earlier contain hardcoded credentials or authentication bypass vulnerability (CWE-798). Successful exploitation allows remote code execution, denial of service, or unauthorized control of the panel. ABB has declared these products end-of-life and will not provide firmware patches. Panel Builder 600 v2.8.0.424 and BSP UN31 v2.31 were released but only apply to newer revision variants not listed in the affected products.
- Network access to the CP600 panel via Ethernet (UDP or TCP, port not specified in advisory)
- Panel must be running BSP UN31 v1.76 or earlier
- No authentication required for exploitation
Patching may require device reboot — plan for process interruption
/api/v1/advisories/d1637dd3-a16f-423d-a6ef-58bdb00960b2Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.