PT-2019-15745 · Abb · Abb Pb610 Panel Builder 600

Publicado

2019-12-18

·

Atualizado

2019-12-31

·

CVE-2019-18994

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier
Description The issue arises due to a lack of file length check in the HMIStudio component, causing it to crash when attempting to load an empty *.JPR application file. An attacker with access to the file system could potentially exploit this to cause application malfunction, such as denial of service.
Recommendations For versions 2.8.0.424 and earlier, consider implementing a file length check before loading *.JPR application files to prevent the HMIStudio component from crashing. As a temporary workaround, restrict access to the file system to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-18994

Produtos afetados

Abb Pb610 Panel Builder 600