// For flags

CVE-2019-18998

Asset Suite Direct Object Reference Access

Severity Score

7.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.

Un control de acceso insuficiente en la interfaz web de ABB Asset Suite versiones 9.0 hasta 9.3, versiones 9.4 anteriores a 9.4.2.6, versiones 9.5 anteriores a 9.5.3.2 y versiĆ³n 9.6.0, permite el acceso completo a objetos referenciados directamente. Un atacante con conocimiento de la URL de un recurso puede acceder al recurso directamente.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-11-15 CVE Reserved
  • 2020-02-17 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-284: Improper Access Control
  • CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hitachienergy
Search vendor "Hitachienergy"
Asset Suite
Search vendor "Hitachienergy" for product "Asset Suite"
>= 9.0.0 <= 9.3.0
Search vendor "Hitachienergy" for product "Asset Suite" and version " >= 9.0.0 <= 9.3.0"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Asset Suite
Search vendor "Hitachienergy" for product "Asset Suite"
>= 9.4 < 9.4.2.6
Search vendor "Hitachienergy" for product "Asset Suite" and version " >= 9.4 < 9.4.2.6"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Asset Suite
Search vendor "Hitachienergy" for product "Asset Suite"
>= 9.5.0 < 9.5.3.2
Search vendor "Hitachienergy" for product "Asset Suite" and version " >= 9.5.0 < 9.5.3.2"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Asset Suite
Search vendor "Hitachienergy" for product "Asset Suite"
9.6.0
Search vendor "Hitachienergy" for product "Asset Suite" and version "9.6.0"
-
Affected