Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE.
An attacker can gain access to salted information to decrypt MQTT information.
This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to salted information to decrypt MQTT information. This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016. | |
| Title | Hard Coded Key used for AES encryption | |
| Weaknesses | CWE-321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ABB
Published: 2025-07-03T16:56:51.070Z
Updated: 2025-07-03T17:54:54.823Z
Reserved: 2025-06-13T14:53:29.571Z
Link: CVE-2025-6071
Updated: 2025-07-03T17:54:40.764Z
Status : Awaiting Analysis
Published: 2025-07-03T17:15:40.373
Modified: 2025-07-08T16:19:11.700
Link: CVE-2025-6071
No data.
ReportizFlow