Stack-based buffer overflow in ABB products - CVE-2019-7231
Published: July 4, 2019 / Updated: July 4, 2019
Vulnerability details
The vulnerability allows an attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when a long string is sent to the IDAL FTP server. An authenticated attacker can send a FTP command string of 472 bytes or more to overflow a buffer, causing an exception that terminates the server.
Affected software
BSP UN30
PB610 Panel Builder 600
How to mitigate CVE-2019-7231
BSP UN30 - update to 2.31
PB610 Panel Builder 600 - update to 2.8.0.424