Input validation error in CP408 Panel Builder TextEditor and CP405 Panel Builder TextEditor - CVE-2018-19008

 

Input validation error in CP408 Panel Builder TextEditor and CP405 Panel Builder TextEditor - CVE-2018-19008

Published: January 17, 2019 / Updated: January 18, 2019


Vulnerability identifier: #VU17075
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-19008
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: ABB
Affected software:
CP408 Panel Builder TextEditor
CP405 Panel Builder TextEditor

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists in the file parser of the Text Editor due to improper prevention of the insertion of specially crafted files. A remote unauthenticated attacker can trick the victim into processing a specially crafted input and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


How to mitigate CVE-2018-19008

Update the affected products to version 2.1.7.21.

Sources