CVE-2019-18995: ABB PB610 HMISimulator does not check content-length of the HTTP request
The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18995?
CVE-2019-18995 is classified as a denial of service vulnerability.
How does CVE-2019-18995 exploit work?
CVE-2019-18995 exploits the failure to validate the content-length field in HTTP requests, allowing for denial of service.
Which versions of ABB PB610 Panel Builder 600 are affected by CVE-2019-18995?
CVE-2019-18995 affects ABB PB610 Panel Builder 600 versions up to and including 2.8.0.424.
How can I mitigate the risks associated with CVE-2019-18995?
To mitigate CVE-2019-18995, update ABB PB610 Panel Builder 600 to a version that addresses this vulnerability.
What are the implications of CVE-2019-18995 for users?
Users affected by CVE-2019-18995 may experience service disruptions due to the denial of service attack exploiting this vulnerability.