PT-2019-2568 · Abb · Abb Idal Ftp Server

Eldar Marcussen

·

Published

2019-06-13

·

Updated

2022-12-01

·

CVE-2019-7230

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ABB IDAL FTP server (affected versions not specified)
Description The issue is related to the mishandling of format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack. This could potentially allow a remote attacker to execute arbitrary code by sending a specially crafted request with a username.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

BDU:2019-02436
CVE-2019-7230

Affected Products

Abb Idal Ftp Server