CVE-2019-7231: Buffer Overflow
The ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This overflow is handled, but terminates the process. An authenticated attacker can send a FTP command string of 472 bytes or more to overflow a buffer, causing an exception that terminates the server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7231?
CVE-2019-7231 is classified as a high severity vulnerability due to its potential to cause denial of service through a buffer overflow.
How do I fix CVE-2019-7231?
To fix CVE-2019-7231, update the ABB PB610 Panel Builder 600 firmware to version 2.8.0.367 or later.
Who can exploit CVE-2019-7231?
An authenticated attacker with access to the ABB IDAL FTP server can exploit CVE-2019-7231.
What impact does CVE-2019-7231 have on affected systems?
Exploitation of CVE-2019-7231 can terminate the FTP server process, causing service disruption.
Which systems are affected by CVE-2019-7231?
CVE-2019-7231 affects ABB PB610 Panel Builder 600 firmware versions from 1.91 up to 2.8.0.367.