PT-2025-18312 · Abb · Abb Anc-Mini+2

Published

2025-04-30

·

Updated

2025-05-01

·

CVE-2024-9877

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ABB ANC versions through 1.1.4 ABB ANC-L versions through 1.1.4 ABB ANC-mini versions through 1.1.4
Description The issue is related to the use of the GET request method with sensitive query strings. This problem affects various ABB products.
Recommendations For ABB ANC versions through 1.1.4, consider avoiding the use of sensitive query strings in GET requests until a patch is available. For ABB ANC-L versions through 1.1.4, restrict access to sensitive data that may be exposed through query strings. For ABB ANC-mini versions through 1.1.4, as a temporary workaround, consider disabling the use of the GET request method for sensitive operations until a fix is provided.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-9877

Affected Products

Abb Anc
Abb Anc-L
Abb Anc-Mini