First published: Mon Jun 24 2019(Updated: )
The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value overflows a buffer and overwrites a Structured Exception Handler (SEH) address. An unauthenticated attacker can submit a Host header value of 2047 bytes or more to overflow the buffer and overwrite the SEH address, which can then be leveraged to execute attacker-controlled code on the server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Abb Pb610 Panel Builder 600 Firmware | >=1.91<=2.8.0.367 | |
ABB PB610 Panel Builder 600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.