CVE-2019-7232: Buffer Overflow
The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value overflows a buffer and overwrites a Structured Exception Handler (SEH) address. An unauthenticated attacker can submit a Host header value of 2047 bytes or more to overflow the buffer and overwrite the SEH address, which can then be leveraged to execute attacker-controlled code on the server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7232?
CVE-2019-7232 is considered critical due to the potential for remote code execution via buffer overflow.
How do I fix CVE-2019-7232?
To fix CVE-2019-7232, you should upgrade to a revised version of the ABB Panel Builder 600 firmware that addresses this vulnerability.
Who is affected by CVE-2019-7232?
CVE-2019-7232 affects users of ABB PB610 Panel Builder 600 Firmware versions between 1.91 and 2.8.0.367.
What type of attack can be executed using CVE-2019-7232?
An attacker can exploit CVE-2019-7232 to perform a denial-of-service attack or potentially execute arbitrary code.
Is authentication required to exploit CVE-2019-7232?
No, CVE-2019-7232 can be exploited by unauthenticated attackers, making it more dangerous.