The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.
2019-12-18T21:15:13.397
2024-11-21T04:33:57.627
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | abb | pb610_panel_builder_600 | ≤ 2.8.0.424 | Yes |