Junglewise Threat Intelligence

CVE-2021-22291: ABB EIBPORT cross-site scripting and session management flaws

CVE-2021-22291 · Severity: high · CVSS 8 · Published 2026-05-28

Vendors: ABB.

Executive brief

ABB EIBPORT is a building management system used to automate facilities based on the KNX standard. A vulnerability in its web interface could allow an attacker to gain unauthorized access to the device, potentially exposing sensitive building data or allowing them to change the device's configuration. This could lead to unauthorized control over building automation systems if the device is not properly isolated from untrusted networks.

Technical details

The vulnerability (CVE-2021-22291) is classified as Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). The root cause is a failure in the firmware's session management to maintain secure identifiers, specifically allowing an attacker to obtain a copy of a session ID. While the attack vector is listed as network-based, the vendor notes that exploitation typically requires the device to be improperly exposed to untrusted networks or the internet. A successful exploit allows an attacker to bypass authentication, access sensitive information, and modify device configurations. ABB has released firmware version 3.9.2 to address these issues by hardening credential verification and session identifier handling.

Affected products

  • ABB EIBPORT V3 KNX (2CLA963710W1001) < 3.9.2
  • ABB EIBPORT V3 KNX (2CSM256242R2001) < 3.9.2
  • ABB EIBPORT V3 KNX GSM (2CLA963720W1001) < 3.9.2

Timeline

  • 2026-05-28: advisory: CISA Advisory ICSA-26-148-03 published.

References