Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2019-8652 | Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly. |
Fixes
Solution
The vulnerability is corrected in the following product versions: Asset Suite 9.4.2.6 Asset Suite 9.5.3.2 Asset Suite 9.6.1
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: ABB
Published:
Updated: 2024-08-05T02:02:39.895Z
Reserved: 2019-11-15T00:00:00
Link: CVE-2019-18998

No data.

Status : Modified
Published: 2020-02-17T19:15:12.150
Modified: 2024-11-21T04:33:57.980
Link: CVE-2019-18998

No data.

No data.