CVE-2019-7227
In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP server functionality to download and upload files.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP server functionality to download and upload files. An unauthenticated attacker can take advantage of the hardcoded or default credential pair exor/exor to become an authenticated attacker.
- CVSS 3.1
- 7.3 HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 8.51% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- abb/pb610 panel builder 600 firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/153396/ABB-IDAL-FTP-Server-Path-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Jun/37Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108886Third Party Advisory, VDB Entry
- https://search.abb.com/library/Download.aspx?DocumentID=3ADR010377&LanguageCode=en&DocumentPartId=&Action=LaunchMitigation, Patch, Vendor Advisory
- https://www.darkmatter.ae/xen1thlabs/abb-idal-ftp-server-path-traversal-vulnerability-xl-19-008/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/153396/ABB-IDAL-FTP-Server-Path-Traversal.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Jun/37Exploit, Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/108886Third Party Advisory, VDB Entry
- https://search.abb.com/library/Download.aspx?DocumentID=3ADR010377&LanguageCode=en&DocumentPartId=&Action=LaunchMitigation, Patch, Vendor Advisory
- https://www.darkmatter.ae/xen1thlabs/abb-idal-ftp-server-path-traversal-vulnerability-xl-19-008/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.