CVE-2019-19104: ABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access Control
The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (URL) , violating the access-control (ACL) rules. This issue allows obtaining sensitive information that may aid in further attacks and privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-19104.
What is the severity of CVE-2019-19104?
The severity of CVE-2019-19104 is critical with a severity value of 9.8.
Which web server is affected by CVE-2019-19104?
The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway is affected by CVE-2019-19104.
How can an attacker exploit CVE-2019-19104?
An attacker can exploit CVE-2019-19104 by accessing specific URLs without authentication, violating the access-control rules.
Is there a fix available for CVE-2019-19104?
To fix CVE-2019-19104, it is recommended to update to the latest firmware version provided by ABB and Busch-Jaeger.