CVE-2019-18250
Estado: ModificadaCrítica (9.8)—
En todas las versiones de ABB Power Generation Information Manager (PGIM) y Plant Connect, el producto afectado es vulnerable a una omisión de autenticación, lo que puede permitir a un atacante omitir remotamente la autenticación y extraer credenciales del dispositivo afectado.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.68%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 8/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-288
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-18250",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "n/a",
"product": "ABB Power Generation Information Manager (PGIM) and Plant Connect All Versions",
"versions": [
{
"status": "affected",
"version": "ABB Power Generation Information Manager (PGIM) and Plant Connect All Versions"
}
]
}
]
}
],
"published": "2019-11-26T00:15:11.780",
"references": [
{
"url": "https://www.us-cert.gov/ics/advisories/icsa-19-318-05",
"tags": [
"Not Applicable",
"Permissions Required",
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://iotsecuritynews.com/abb-power-generation-information-manager-pgim-and-plant-connect/",
"tags": [
"Third Party Advisory"
],
"source": "nvd@nist.gov"
},
{
"url": "https://www.us-cert.gov/ics/advisories/icsa-19-318-05",
"tags": [
"Not Applicable",
"Permissions Required",
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-288"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract credentials from the affected device."
},
{
"lang": "es",
"value": "En todas las versiones de ABB Power Generation Information Manager (PGIM) y Plant Connect, el producto afectado es vulnerable a una omisión de autenticación, lo que puede permitir a un atacante omitir remotamente la autenticación y extraer credenciales del dispositivo afectado."
}
],
"lastModified": "2026-06-17T02:24:42.080",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:abb:plant_connect:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2376DF85-21FD-4C6A-A9C1-B1E5FF276866"
},
{
"criteria": "cpe:2.3:a:abb:power_generation_information_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "928D741D-5A9A-4EB9-827A-6DF53D7BBBD0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}