First published: Wed Apr 30 2025(Updated: )
: Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
ABB ANC | <=1.1.4 | |
ABB ANC | <=1.1.4 | |
ABB ANC | <=1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9877 is considered a significant vulnerability due to its potential to expose sensitive information via GET request methods.
To mitigate CVE-2024-9877, it is recommended to upgrade to a version of the ABB ANC, ANC-L, or ANC-mini software that is later than 1.1.4.
CVE-2024-9877 affects ABB ANC, ABB ANC-L, and ABB ANC-mini versions up to and including 1.1.4.
CVE-2024-9877 allows attackers to potentially access sensitive data that is transmitted through query strings in GET requests.
While the best solution is to upgrade, mitigating the use of GET requests for sensitive information can serve as a temporary workaround for CVE-2024-9877.