Description
The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
http://search.abb.com/library/Download.aspx?DocumentID=3ADR010466&LanguageCode=en&DocumentPartId=&Action=Launch
Scores
CVSS v3
4.3
EPSS
0.0088
EPSS Percentile
75.5%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Details
CWE
CWE-20
Status
published
Products (1)
abb/pb610_panel_builder_600
< 2.8.0.424
Published
Dec 18, 2019
Tracked Since
Feb 18, 2026