CVE-2022-0010
Estado: ModificadaMedia (5.5)—
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools.
An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to exploit this vulnerability to gain control of system nodes.
This issue affects QCS 800xA: from 1.0;0 through 6.1SP2; QCS AC450: from 1.0;0 through 5.1SP2; Platform Engineering Tools: from 1.0:0 through 2.3.0.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.23%
- Percentil entre todas las CVEs puntuadas: 12
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-532
- CWE-532
Referencias
- https://search.abb.com/library/Download.aspx?DocumentID=3BUS221709&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.108646530.1437951308.1684739395-1142547495.1678209228
- https://search.abb.com/library/Download.aspx?DocumentID=3BUS221709&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.108646530.1437951308.1684739395-1142547495.1678209228
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-0010",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-0010",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-21T21:42:53.592481Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cybersecurity@ch.abb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cybersecurity@ch.abb.com",
"affectedData": [
{
"vendor": "ABB",
"product": "QCS 800xA",
"versions": [
{
"status": "affected",
"version": "1.0;0",
"versionType": "patch",
"lessThanOrEqual": "6.1SP2"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "ABB",
"product": "QCS AC450",
"versions": [
{
"status": "affected",
"version": "1.0;0",
"versionType": "patch",
"lessThanOrEqual": "5.1SP2"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "ABB",
"product": "Platform Engineering Tools",
"versions": [
{
"status": "affected",
"version": "1.0:0",
"versionType": "patch",
"lessThanOrEqual": "2.3.0"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-05-22T08:15:08.920",
"references": [
{
"url": "https://search.abb.com/library/Download.aspx?DocumentID=3BUS221709&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.108646530.1437951308.1684739395-1142547495.1678209228",
"tags": [
"Vendor Advisory"
],
"source": "cybersecurity@ch.abb.com"
},
{
"url": "https://search.abb.com/library/Download.aspx?DocumentID=3BUS221709&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.108646530.1437951308.1684739395-1142547495.1678209228",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cybersecurity@ch.abb.com",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools.\n\n\nAn attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to exploit this vulnerability to gain control of system nodes. \n\nThis issue affects QCS 800xA: from 1.0;0 through 6.1SP2; QCS AC450: from 1.0;0 through 5.1SP2; Platform Engineering Tools: from 1.0:0 through 2.3.0.\n\n"
}
],
"lastModified": "2026-06-17T04:19:52.643",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:abb:platform_engineering_tools:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B0469275-C1B5-45EE-B4A9-DE1F500E04C6",
"versionEndIncluding": "2.3.0",
"versionStartIncluding": "1.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:abb:qcs_800xa_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F25CD2B4-140C-49C4-BEBD-9021CAD12FE9",
"versionEndIncluding": "5.1.0",
"versionStartIncluding": "1.0.0"
},
{
"criteria": "cpe:2.3:o:abb:qcs_800xa_firmware:5.1.0:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32217B3E-F886-48A1-8987-A92DA4E54A9A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:abb:qcs_800xa:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "44BDFBF8-88D6-45D9-965F-85CFD002F316"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:abb:qcs_ac450_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24106F4D-2DF1-417E-9FF1-DD212E1F6F27",
"versionEndIncluding": "6.1.0",
"versionStartIncluding": "1.0.0"
},
{
"criteria": "cpe:2.3:o:abb:qcs_ac450_firmware:6.1.0:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03FA9720-A525-4F4B-9486-C346C258B4DE"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:abb:qcs_ac450:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "79CCB4FA-2651-4E96-925F-772E3EAFA593"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cybersecurity@ch.abb.com"
}