First published: Wed Feb 13 2019(Updated: )
The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser of the Text Editor wherein the application doesn't properly prevent the insertion of specially crafted files which could allow arbitrary code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Abb CP400PB | <=2.0.7.05 | |
ABB CP400PB |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19008 is classified as a critical vulnerability due to its potential for arbitrary code execution.
To mitigate CVE-2018-19008, update to a version of ABB CP400 Panel Builder later than 2.0.7.05.
ABB CP400 Panel Builder versions 2.0.7.05 and earlier are affected by CVE-2018-19008.
CVE-2018-19008 is a file parser vulnerability that can lead to arbitrary code execution.
The vendor for CVE-2018-19008 is ABB, specifically for their CP400 Panel Builder software.