Back to search
CVE-2019-7227
Published: Jun 27, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP server functionality to download and upload files. An unauthenticated attacker can take advantage of the hardcoded or default credential pair exor/exor to become an authenticated attacker.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20190624 XL-19-008 - ABB IDAL FTP Server Path Traversal Vulnerability
mailing-list
x_refsource_FULLDISC
108886
vdb-entry
x_refsource_BID
20190620 XL-19-008 - ABB IDAL FTP Server Path Traversal Vulnerability
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now