First published: Tue Jun 05 2018(Updated: )
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the configuration files and application pages without authentication.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Beronet Voice Over Internet Protocol Gateways Firmware | <=3.39 | |
ABB IP Gateway Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-7931 is considered high due to unauthorized access to sensitive configuration files.
To fix CVE-2017-7931, upgrade the ABB IP GATEWAY firmware to version 3.40 or later, which addresses the vulnerability.
CVE-2017-7931 affects ABB IP GATEWAY firmware versions up to and including 3.39.
Yes, CVE-2017-7931 allows a malicious user to access configuration files without authentication.
An attacker exploiting CVE-2017-7931 can access sensitive application pages and configuration files, potentially compromising system security.