CVE-2019-7231
ABB IDAL FTP Server Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This overflow is handled, but terminates the process. An authenticated attacker can send a FTP command string of 472 bytes or more to overflow a buffer, causing an exception that terminates the server.
El servidor FTP IDAL de ABB, es vulnerable a un desbordamiento de búfer cuando una cadena larga es enviada por un atacante autenticado. Este desbordamiento es manejado, pero finaliza el proceso. Un atacante autenticado puede enviar una cadena de comando FTP de 472 bytes o más para desbordar un búfer, causando una excepción que termina el servidor.
The IDAL FTP server is vulnerable to a buffer overflow where a large string is sent by an authenticated attacker that causes a buffer overflow. This overflow is handled, but terminates the process. An authenticated attacker can send a FTP command string of 472 bytes or more to overflow a buffer causing an exception that terminates the server. An unauthenticated attacker can take advantage of the hardcoded or default credential pair exor/exor to become an authenticated attacker.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-30 CVE Reserved
- 2019-06-21 CVE Published
- 2024-06-17 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/108886 | Third Party Advisory | |
https://www.darkmatter.ae/xen1thlabs/published-advisories | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://packetstormsecurity.com/files/153395/ABB-IDAL-FTP-Server-Buffer-Overflow.html | 2024-08-04 | |
http://seclists.org/fulldisclosure/2019/Jun/35 | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://search.abb.com/library/Download.aspx?DocumentID=3ADR010377&LanguageCode=en&DocumentPartId=&Action=Launch | 2022-11-30 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Abb Search vendor "Abb" | Pb610 Panel Builder 600 Firmware Search vendor "Abb" for product "Pb610 Panel Builder 600 Firmware" | >= 1.91 <= 2.8.0.367 Search vendor "Abb" for product "Pb610 Panel Builder 600 Firmware" and version " >= 1.91 <= 2.8.0.367" | - |
Affected
| in | Abb Search vendor "Abb" | Pb610 Panel Builder 600 Search vendor "Abb" for product "Pb610 Panel Builder 600" | - | - |
Safe
|