CVE-2022-31219
ABB Drive Composer pro vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2022-31219) affects ABB's Drive Composer software, which was discovered in 2022. This security flaw allows a low-privileged user to create and write files anywhere on the file system with SYSTEM privileges through the Drive Composer installer's repair operation (CISA Advisory, ZDI Advisory).

Technical details

The vulnerability is classified as an Improper Privilege Management issue (CWE-269). It has been assigned a CVSS v3 base score of 7.3, with the vector string AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H. This indicates a local attack vector, low attack complexity, requiring low privileges and user interaction, with potential for high impacts on confidentiality, integrity, and availability (CISA Advisory).

Impact

Successful exploitation of this vulnerability could allow an attacker to escalate privileges and execute arbitrary code in the context of SYSTEM, potentially gaining complete control over the affected system. The vulnerability affects multiple versions of ABB Drive Composer Entry and Pro (versions 2.0 to 2.7), ABB Automation Builder (versions 1.1.0 to 2.5.0), and Mint Workbench (Builds 5866 and prior) (ZDI Advisory, CISA Advisory).

Exploitability

The vulnerability requires an attacker to first obtain the ability to execute low-privileged code on the target system. The exploitation involves abusing the Drive Composer installer's repair operation functionality. No known public exploits specifically targeting this vulnerability have been reported, and it is not exploitable remotely (CISA Advisory, ZDI Advisory).

Mitigation and workarounds

ABB has released updates to address this vulnerability. Users are recommended to update to Drive Composer v2.7.1 or later, Automation Builder 2.5.1 or later, and Mint Workbench Build 5868 or later. Additionally, CISA recommends minimizing network exposure for control system devices, ensuring they are not accessible from the Internet, and using secure methods like VPNs when remote access is required (CISA Advisory).

Additional resources


SourceThis report was generated using AI

Related ABB Drive Composer pro vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-31219HIGH7.8
  • ABB Drive Composer pro logoABB Drive Composer pro
  • cpe:2.3:a:abb:drive_composer:*:*:*:*:pro:*:*:*
NoYesJun 15, 2022
CVE-2022-31218HIGH7.8
  • ABB Drive Composer pro logoABB Drive Composer pro
  • cpe:2.3:a:abb:drive_composer:*:*:*:*:pro:*:*:*
NoYesJun 15, 2022
CVE-2022-31217HIGH7.8
  • ABB Drive Composer pro logoABB Drive Composer pro
  • cpe:2.3:a:abb:drive_composer:*:*:*:*:pro:*:*:*
NoYesJun 15, 2022
CVE-2022-31216HIGH7.8
  • ABB Drive Composer pro logoABB Drive Composer pro
  • cpe:2.3:a:abb:drive_composer:*:*:*:*:pro:*:*:*
NoYesJun 15, 2022
CVE-2022-3573MEDIUM5.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJan 12, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management