CVE-2021-22291
8.0ABB · EIBPORT V3 KNX and EIBPORT V3 KNX GSM
A cross-site scripting vulnerability exists in ABB EIBPORT V3 KNX and KNX GSM devices, allowing attackers to inject malicious scripts into web pages.
Executive summary
An improper input neutralization vulnerability in ABB EIBPORT V3 devices permits cross-site scripting attacks that could compromise user sessions and interface integrity.
Vulnerability
The product fails to properly neutralize user-supplied input during web page generation, leading to CWE-79 (Cross-site Scripting). Based on the CVSS vector (PR:L), this vulnerability requires a low-privileged authenticated user to trigger the malicious script in the context of an active session.
Business impact
Successful exploitation allows an attacker to execute arbitrary scripts in the victim's browser, potentially leading to session hijacking, unauthorized actions, or the theft of sensitive configuration data. With a CVSS score of 8.0, this is classified as a High severity issue, posing significant risks to the operational control and management security of the affected industrial automation systems.
Remediation
Immediate Action: Update all instances of ABB EIBPORT V3 KNX and EIBPORT V3 KNX GSM to firmware version 3.9.2 or later as specified in the vendor security advisory.
Proactive Monitoring: Review web server and application access logs for unusual patterns, such as unexpected script tags or encoded characters in URL parameters and input fields.
Compensating Controls: Deploy a Web Application Firewall (WAF) with configured rules to detect and block common cross-site scripting attack patterns targeting the device web interface.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Given the High severity rating of this vulnerability, administrators should prioritize the firmware update to version 3.9.2 to eliminate the underlying injection flaw. Failure to patch these devices leaves the management interface susceptible to manipulation, which could lead to broader compromise of the connected KNX control environment.
More ABB CVEs
Sources
Originally found and disclosed by ABB acknowledges and thanks Psytester for responsibly disclosing the vulnerabilities and helping to verify the resolving, per the CVE Program record.