CVE-2019-7226
published 2019-06-27CVE-2019-7226: The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions…
PriorityP356high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
5.26%
91.6th percentile
The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. Specifically, /cgi/loginDefaultUser creates a session in an authenticated state and returns the session ID along with what may be the username and cleartext password of the user. An attacker can then supply an IDALToken value in a cookie, which will allow them to perform privileged operations such as restarting the service with /cgi/restart. A GET request to /cgi/loginDefaultUser may result in "1 #S_OK IDALToken=532c8632b86694f0232a68a0897a145c admin admin" or a similar response.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | pb610_panel_builder_600_firmware | 1.91 – 2.8.0.367 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.8MEDIUMAV:A/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fwqr-ff3c-hg7r: The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged f
ghsa_unreviewed·2022-05-24
CVE-2019-7226 [HIGH] CWE-287 GHSA-fwqr-ff3c-hg7r: The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged f
The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. Specifically, /cgi/loginDefaultUser creates a session in an authenticated state and returns the session ID along with what may be the username and cleartext password of the user. An attacker can then supply an IDALToken value in a cookie, which will allow them to perform privileged operations such as restarting the service with /cgi/restart. A GET request to /cgi/loginDefaultUser may result in "1 #S_OK IDALToken=532c8632b86694f0232a68a0897a145c admin admin" or a similar response.
CISA ICS
ABB PB610 Panel Builder 600
cisa_ics·2019-06-27·CVSS 8.8
[HIGH] ABB PB610 Panel Builder 600
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB PB610 Panel Builder 600
Last RevisedJune 27, 2019
Alert CodeICSA-19-178-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Low skill level to exploit
- Vendor: ABB
- Equipment: PB610 Panel Builder 600
- Vulnerabilities: Use of Hard-coded Credentials, Improper Authentication, Relative Path Traversal, Improper Input Validation, Stack-based Buffer Overflow
## 2. RISK EVALUATION
An attacker who successfully exploits these vulnerabilities could prevent legitimate access to an affected system node, remotely cause an affected system node to stop, take control of an affecte
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/153402/ABB-IDAL-HTTP-Server-Authentication-Bypass.htmlhttp://seclists.org/fulldisclosure/2019/Jun/39http://www.securityfocus.com/bid/108886https://www.darkmatter.ae/xen1thlabs/abb-idal-http-server-authentication-bypass-vulnerability-xl-19-010/http://packetstormsecurity.com/files/153402/ABB-IDAL-HTTP-Server-Authentication-Bypass.htmlhttp://seclists.org/fulldisclosure/2019/Jun/39http://www.securityfocus.com/bid/108886https://www.darkmatter.ae/xen1thlabs/abb-idal-http-server-authentication-bypass-vulnerability-xl-19-010/
2019-06-27
Published