CVE-2025-6071
CWE-321漏洞涉及硬编码加密密钥,攻击者可利用盐值解密MQTT信息。ABB建议非配置时禁用REST接口,默认禁用无风险。RMC-100不适用于公共网络,需私有网络访问才可被利用,推荐网络分段以提升安全性。 2025-7-15 09:44:0 Author: claroty.com(查看原文) 阅读量:2 收藏

Medium Threat

CWE-321 USE OF HARD-CODED CRYPTOGRAPHIC KEY:

An attacker can gain access to salted information to decrypt MQTT information.

ABB recommends disabling the REST interface when it is not being used to configure the MQTT functionality. By default, when the REST interface is disabled so there is no risk. The RMC-100 is not intended for access over public networks such as the Internet. An attacker would need access to the user's private control network to exploit these vulnerabilities. Proper network segmentation is recommended.


文章来源: https://claroty.com/team82/disclosure-dashboard/cve-2025-6071
如有侵权请联系:admin#unsafe.sh