CVE-2022-29483
ABB e-Design vulnerability analysis and mitigation

Overview

CVE-2022-29483 is a security vulnerability discovered in ABB e-Design software that was disclosed on June 28, 2022. This vulnerability is classified as an Incorrect Default Permissions issue (CWE-276) affecting all versions of ABB e-Design prior to 1.12.2.0006. The vulnerability received a CVSS v3.1 base score of 7.8 (High) (CISA Advisory, NVD).

Technical details

The vulnerability stems from incorrect default permissions in the e-Design installer that could be exploited by creating a symbolic link, allowing an attacker to abuse the installer to delete files. The vulnerability has been assigned a CVSS vector string of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating local access required, low attack complexity, low privileges required, and high impact on confidentiality, integrity, and availability (ZDI Advisory).

Impact

If successfully exploited, this vulnerability allows an attacker to install malicious software that executes with SYSTEM permissions, potentially compromising the confidentiality, integrity, and availability of the target machine. The attacker could escalate privileges and execute arbitrary code in the context of SYSTEM (CISA Advisory, ZDI Advisory).

Mitigation and workarounds

ABB has released version 1.12.2.0006 to address this vulnerability. Until the update can be applied, it is recommended that machine owners prevent other users from logging into the system and ensure the machine is not left unlocked when not in use (CISA Advisory).

Additional resources


SourceThis report was generated using AI

Related ABB e-Design vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-29483HIGH7.8
  • ABB e-DesignABB e-Design
  • cpe:2.3:a:abb:e-design
NoNoJun 02, 2022
CVE-2022-28702MEDIUM5.5
  • ABB e-DesignABB e-Design
  • cpe:2.3:a:abb:e-design
NoNoJun 02, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management