Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-18994

Опубликовано: 18 дек. 2019
Источник: nvd
CVSS3: 3.9
CVSS3: 6.5
CVSS2: 3.5
EPSS Низкий

Описание

Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:abb:pb610_panel_builder_600:*:*:*:*:*:*:*:*
Версия до 2.8.0.424 (включая)

EPSS

Процентиль: 43%
0.00205
Низкий

3.9 Low

CVSS3

6.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-20
CWE-20

Связанные уязвимости

github
больше 3 лет назад

Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such as denial of service.

EPSS

Процентиль: 43%
0.00205
Низкий

3.9 Low

CVSS3

6.5 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-20
CWE-20