CVE-2019-18997

low-risk
Published 2019-12-18

The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus potentially supporting unauthorized file access.

Do I need to act?

-
0.40% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.3/10 Medium
ADJACENT_NETWORK / LOW complexity

Affected Products (1)

Pb610 Panel Builder 600

Affected Vendors

Abb
22
/ 100
low-risk
Severity 15/34 · Moderate
Exploitability 2/34 · Minimal
Exposure 5/34 · Minimal