4.1
CVSSv2

CVE-2019-7227

Published: 27/06/2019 Updated: 30/11/2022
CVSS v2 Base Score: 4.1 | Impact Score: 4.9 | Exploitability Score: 5.1
CVSS v3 Base Score: 7.3 | Impact Score: 5.2 | Exploitability Score: 2.1
VMScore: 365
Vector: AV:A/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP server functionality to download and upload files. An unauthenticated attacker can take advantage of the hardcoded or default credential pair exor/exor to become an authenticated attacker.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

abb pb610_panel_builder_600_firmware

Exploits

The IDAL FTP server fails to ensure that directory change requests do not change to locations outside of the FTP servers root directory An authenticated attacker can simply traverse outside the server root directory by changing the directory with "cd " An authenticated attacker can traverse to arbitrary directories on the hard disk and then use ...