First published: Thu Jun 27 2019(Updated: )
The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Abb Pb610 Panel Builder 600 Firmware | >=1.91<=2.8.0.367 | |
ABB PB610 Panel Builder 600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.