First published: Wed Dec 18 2019(Updated: )
The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
ABB Panel Builder 600 | <=2.8.0.424 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18995 is classified as a denial of service vulnerability.
CVE-2019-18995 exploits the failure to validate the content-length field in HTTP requests, allowing for denial of service.
CVE-2019-18995 affects ABB PB610 Panel Builder 600 versions up to and including 2.8.0.424.
To mitigate CVE-2019-18995, update ABB PB610 Panel Builder 600 to a version that addresses this vulnerability.
Users affected by CVE-2019-18995 may experience service disruptions due to the denial of service attack exploiting this vulnerability.