5.8
CVSSv2

CVE-2019-7228

Published: 27/06/2019 Updated: 30/11/2022
CVSS v2 Base Score: 5.8 | Impact Score: 6.4 | Exploitability Score: 6.5
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

abb pb610_panel_builder_600_firmware

Exploits

The IDAL HTTP server is vulnerable to memory corruption through insecure use of user supplied format strings An attacker can abuse this functionality to bypass authentication or execute code on the server The IDAL HTTP server does not safely handle username or cookie strings during the authentication process Attempting to authenticate with the u ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> XL-19-012 - ABB IDAL HTTP Server Uncontrolled Format String Vulnerability <!--X-Subject-Header-End--> <!--X-Head-of-Me ...