CVE-2019-18996: ABB PB610 HMIStudio accepts malicious DLL file in an application
Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-18996?
CVE-2019-18996 has been classified with a high severity level due to the potential for remote code execution.
How do I fix CVE-2019-18996?
To fix CVE-2019-18996, upgrade to a version of ABB Panel Builder 600 that is later than 2.8.0.424.
What systems are affected by CVE-2019-18996?
CVE-2019-18996 affects ABB Panel Builder 600 version 2.8.0.424 and earlier.
What type of attack can be executed using CVE-2019-18996?
CVE-2019-18996 allows an attacker to execute arbitrary code due to mishandling of DLL path settings.
Who is at risk from CVE-2019-18996?
Users and administrators of affected versions of ABB Panel Builder 600 are at risk from CVE-2019-18996.