CVE-2019-7230: High severity abb pb610 panel builder 600 firmware vulnerability
The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7230?
CVE-2019-7230 has a medium severity rating due to its potential to crash the ABB IDAL FTP server and leak sensitive memory information.
How do I fix CVE-2019-7230?
To mitigate CVE-2019-7230, update the ABB IDAL FTP server to a version above 2.8.0.367 or implement input validation to reject malicious format strings in usernames.
Which ABB software is affected by CVE-2019-7230?
CVE-2019-7230 affects the ABB PB610 Panel Builder 600 firmware versions between 1.91 and 2.8.0.367.
What type of vulnerability is CVE-2019-7230?
CVE-2019-7230 is a format string vulnerability that occurs during the authentication process of the ABB IDAL FTP server.
Is CVE-2019-7230 exploitable remotely?
Yes, CVE-2019-7230 is exploitable remotely as it involves sending crafted usernames during authentication to the FTP server.