CVE CVE-2018-18995 Mappings

Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, including conducting device resets, reading or modifying registers, and changing configuration settings such as IP addresses.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name
CVE-2018-18995 ABB GATE-E1 and GATE-E2 secondary_impact T0816 Device Restart/Shutdown
CVE-2018-18995 ABB GATE-E1 and GATE-E2 secondary_impact T1529 System Shutdown/Reboot
CVE-2018-18995 ABB GATE-E1 and GATE-E2 secondary_impact T0855 Unauthorized Command Message
CVE-2018-18995 ABB GATE-E1 and GATE-E2 secondary_impact T0836 Modify Parameter
CVE-2018-18995 ABB GATE-E1 and GATE-E2 secondary_impact T1213 Data from Information Repositories