PT-2018-10006 · Abb · Abb Panel Builder 800

Michael Deplante

+1

·

Published

2018-07-18

·

Updated

2019-10-09

·

CVE-2018-10616

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ABB Panel Builder 800 all versions
Description The issue is related to improper input validation, which may allow an attacker to insert and run arbitrary code on a computer where the affected product is used. This can lead to remote code execution vulnerabilities. Various components and modules within the ABB Panel Builder 800 are affected, including those related to ModBus, TCP/IP addresses, and user settings. The vulnerability can be exploited through stack-based or heap-based buffer overflows, as well as format string vulnerabilities.
Recommendations As a temporary workaround, consider disabling the vulnerable components or restricting access to them until a patch is available. For versions that are affected by the improper input validation vulnerability, ensure that all inputs are properly validated and sanitized to prevent arbitrary code execution. Restrict access to the TCP IP Address and IPAddress parameters in the affected modules to minimize the risk of exploitation. Avoid using the UserSettings and CommandLineOptions in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10616
ZDI-18-882
ZDI-18-883
ZDI-18-884
ZDI-18-885
ZDI-18-886
ZDI-18-887
ZDI-18-888
ZDI-18-889
ZDI-18-891
ZDI-18-892
ZDI-18-893
ZDI-18-894
ZDI-18-895
ZDI-18-896
ZDI-18-897
ZDI-18-898
ZDI-18-899
ZDI-18-900
ZDI-18-901
ZDI-18-902
ZDI-18-903
ZDI-18-904
ZDI-18-905
ZDI-18-906
ZDI-18-907
ZDI-18-908
ZDI-18-909
ZDI-18-910
ZDI-18-911
ZDI-18-912
ZDI-18-914

Affected Products

Abb Panel Builder 800