CVE-2019-7227 describes a path traversal vulnerability in the ABB IDAL FTP server, affecting ABB PB610 Panel Builder 600 and its firmware. An authenticated attacker can leverage "CWD ../" to access arbitrary directories and perform file operations. Unauthenticated attackers can gain initial access using hardcoded or default credentials (exor/exor). This vulnerability has a CVSS score of 7.3 (HIGH), indicating a network-adjacent attack with low complexity and privileges, leading to high confidentiality and integrity impacts. While there is no known active exploitation, exploit code, or Metasploit/Nuclei modules, its EPSS score suggests a low probability of exploitation. Despite its severity, CVE-2019-7227 has garnered minimal community discussion and media coverage, with no evidence of being added to the CISA KEV catalog or other hot lists. Organizations using affected ABB products should prioritize patching to mitigate potential risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.91, <= 2.8.0.367CPE matchmatch criteria | cpe:2.3:o:abb:pb610_panel_builder_600_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.