Open
Description
{
"id": 41,
"title": "RVD#41: Poor transport encryption",
"type": "vulnerability",
"description": "On previous firmware versions of ABB's Service BoxThe device has outdated cryptographic libraries or ciphers, as explained above, also fall in this category.Web-based administration interfaces are not always on HTTPS despite being the main access point for management. Credits to Federico Maggi, Trend Micro Forward-Looking Threat Research, Davide Quarta, Marcello Pogliani, Mario Polino, Andrea M. Zanchettin, and Stefano Zanero, Politecnico di Milano",
"cwe": "CWE-Inadequate Encryption Strength (CWE-326)",
"cve": "None",
"keywords": [
"components hardware",
"robot component: ABB's Service Box",
"severity: high",
"state: new",
"vendor: ABB",
"vulnerability"
],
"system": "ABB's Service Box",
"vendor": "ABB",
"severity": {
"rvss-score": "None",
"rvss-vector": "RVSS:1.0/AV:RN/AC:L/PR:N/UI:N/Y:T/S:U/C:H/I:N/A:N/H:N",
"severity-description": "",
"cvss-score": 0,
"cvss-vector": ""
},
"links": [
"https://github.com/aliasrobotics/RVD/issues/41"
],
"flaw": {
"phase": "unknown",
"specificity": "N/A",
"architectural-location": "N/A",
"application": "N/A",
"subsystem": "N/A",
"package": "N/A",
"languages": "None",
"date-detected": "2017-05-03",
"detected-by": "",
"detected-by-method": "N/A",
"date-reported": "2017-05-03",
"reported-by": "",
"reported-by-relationship": "N/A",
"issue": "https://github.com/aliasrobotics/RVD/issues/41",
"reproducibility": "",
"trace": null,
"reproduction": "",
"reproduction-image": ""
},
"exploitation": {
"description": "",
"exploitation-image": "",
"exploitation-vector": ""
},
"mitigation": {
"description": "",
"pull-request": "",
"date-mitigation": null
}
}