You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
id: 3324title: 'RVD#3324: ABB IRC5 FTP daemon in VxWorks does not close the TCP connection after a number of failed login attempts'type: vulnerabilitydescription: The FTP daemon in Wind River VxWorks does not close the TCP connectionafter a number of failed login attempts, which makes it easier for remote attackersto obtain access via a brute-force attack. This was previously recorded for VxWorksat CVE-2010-2968 however from our results ABB products including all IRC5 (controller)supported robots including IRB140 are affected.cwe: CWE-264cve: CVE-2010-2968keywords:
- IRC5, FTP, Autenticationsystem: IRB140, IRC5, Robotware_5.09, VxWorks5.5.1vendor: ABBseverity:
rvss-score: 10.0rvss-vector: RVSS:1.0/AV:RN/AC:L/PR:N/UI:N/Y:M/S:U/C:H/I:L/A:H/H:U/severity-description: Criticalcvss-score: 9.8cvss-vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:Hlinks:
- https://nvd.nist.gov/vuln/detail/CVE-2010-2968
- https://github.com/aliasrobotics/RVD/issues/3324flaw:
phase: testingspecificity: general-issuearchitectural-location: Platform codeapplication: VxWorkssubsystem: FTP Daemonpackage: N/Alanguages: Nonedate-detected: 2020-05-19detected-by: Alfonso Glera, Victor Mayoral Vilches (Alias Robotics)detected-by-method: testing dynamic, Browser.date-reported: '2020-07-15'reported-by: Victor Mayoral Vilchesreported-by-relationship: security researcherissue: https://github.com/aliasrobotics/RVD/issues/3324reproducibility: Alwaystrace: Not disclosedreproduction: Not disclosedreproduction-image: Not disclosedexploitation:
description: Not disclosedexploitation-image: Not disclosedexploitation-vector: Not disclosedexploitation-recipe: ''mitigation:
description: Not disclosedpull-request: Not discloseddate-mitigation: null
The text was updated successfully, but these errors were encountered:
rvd-bot
changed the title
ABB IRC5 FTP daemon in VxWorks does not close the TCP connection after a number of failed login attempts
RVD#3324: ABB IRC5 FTP daemon in VxWorks does not close the TCP connection after a number of failed login attempts
Jul 15, 2020
The text was updated successfully, but these errors were encountered: