PT-2025-18312 · Abb · Abb Anc-Mini+2
Published
2025-04-30
·
Updated
2025-05-01
·
CVE-2024-9877
CVSS v3.1
4.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ABB ANC versions through 1.1.4
ABB ANC-L versions through 1.1.4
ABB ANC-mini versions through 1.1.4
Description
The issue is related to the use of the GET request method with sensitive query strings. This problem affects various ABB products.
Recommendations
For ABB ANC versions through 1.1.4, consider avoiding the use of sensitive query strings in GET requests until a patch is available.
For ABB ANC-L versions through 1.1.4, restrict access to sensitive data that may be exposed through query strings.
For ABB ANC-mini versions through 1.1.4, as a temporary workaround, consider disabling the use of the GET request method for sensitive operations until a fix is provided.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abb Anc
Abb Anc-L
Abb Anc-Mini