PT-2019-15745 · Abb · Abb Pb610 Panel Builder 600
Publicado
2019-12-18
·
Atualizado
2019-12-31
·
CVE-2019-18994
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier
Description
The issue arises due to a lack of file length check in the HMIStudio component, causing it to crash when attempting to load an empty *.JPR application file. An attacker with access to the file system could potentially exploit this to cause application malfunction, such as denial of service.
Recommendations
For versions 2.8.0.424 and earlier, consider implementing a file length check before loading *.JPR application files to prevent the HMIStudio component from crashing. As a temporary workaround, restrict access to the file system to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Abb Pb610 Panel Builder 600