CVE-2019-18996

Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.
Configurations

Configuration 1 (hide)

cpe:2.3:a:abb:pb610_panel_builder_600:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:33

Type Values Removed Values Added
CVSS v2 : 4.4
v3 : 7.8
v2 : 4.4
v3 : 7.1
References () http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch - Third Party Advisory () http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch - Third Party Advisory

Information

Published : 2019-12-18 21:15

Updated : 2024-11-21 04:33


NVD link : CVE-2019-18996

Mitre link : CVE-2019-18996

CVE.ORG link : CVE-2019-18996


JSON object : View

Products Affected

abb

  • pb610_panel_builder_600
CWE
CWE-424

Improper Protection of Alternate Path

CWE-426

Untrusted Search Path