7.1
CVE-2019-18998
- EPSS 0.13%
- Veröffentlicht 17.02.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:33:57
- Quelle cybersecurity@ch.abb.com
- CVE-Watchlists
- Unerledigt
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hitachienergy ≫ Asset Suite Version >= 9.0.0 <= 9.3.0
Hitachienergy ≫ Asset Suite Version >= 9.4 < 9.4.2.6
Hitachienergy ≫ Asset Suite Version >= 9.5.0 < 9.5.3.2
Hitachienergy ≫ Asset Suite Version9.6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.332 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
|
| nvd@nist.gov | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|
| cybersecurity@ch.abb.com | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.