CVE-2019-18996 HIGH

CVE-2019-18996: ABB PB610 HMIStudio accepts malicious DLL file in an application

Vendor Abb
Product PB610 Panel Builder 600
Weakness CWE-424
Published December 18, 2019
Last update August 5, 2024

CVSS base score

7.1/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L

What the vulnerability does

01Description

Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.

Key dates

02Disclosure timeline

December 18, 2019 CVE published
August 5, 2024 Record updated