PT-2019-15747 · Abb · Abb Pb610 Panel Builder 600

CVE-2019-18996

·

Publicado

2019-12-18

·

Atualizado

2023-02-03

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier
Description The issue concerns the HMIStudio component of ABB PB610 Panel Builder 600, where path settings accept DLLs from outside the program directory. This could potentially allow an attacker with local file system access to execute code within the application's context.
Recommendations For ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier, consider restricting the path settings in the HMIStudio component to only accept DLLs from within the program directory until a fix is available.

Correção

Untrusted Search Path

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-18996

Produtos afetados

Abb Pb610 Panel Builder 600