CVE-2019-19107: ABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Information Exposure
The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidden when displayed).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19107?
CVE-2019-19107 is a vulnerability in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway that allows the password to be transferred in plaintext.
What is the severity of CVE-2019-19107?
CVE-2019-19107 has a severity rating of 5.5 (medium).
Which software versions are affected by CVE-2019-19107?
ABB Telephone Gateway TG/S 3.2 firmware and Busch-Jaeger 6186/11 firmware are affected by CVE-2019-19107.
How can I mitigate CVE-2019-19107?
To mitigate CVE-2019-19107, it is recommended to update the firmware of ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway to the latest version provided by the vendor.
Where can I find more information about CVE-2019-19107?
More information about CVE-2019-19107 can be found at the following reference link: [https://search.abb.com/library/Download.aspx?DocumentID=9AKK107680A3921&LanguageCode=en&DocumentPartId=&Action=Launch](https://search.abb.com/library/Download.aspx?DocumentID=9AKK107680A3921&LanguageCode=en&DocumentPartId=&Action=Launch)