Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-7227

28
FAUCET Score

CVE-2019-7227 describes a path traversal vulnerability in the ABB IDAL FTP server, affecting ABB PB610 Panel Builder 600 and its firmware. An authenticated attacker can leverage "CWD ../" to access arbitrary directories and perform file operations. Unauthenticated attackers can gain initial access using hardcoded or default credentials (exor/exor). This vulnerability has a CVSS score of 7.3 (HIGH), indicating a network-adjacent attack with low complexity and privileges, leading to high confidentiality and integrity impacts. While there is no known active exploitation, exploit code, or Metasploit/Nuclei modules, its EPSS score suggests a low probability of exploitation. Despite its severity, CVE-2019-7227 has garnered minimal community discussion and media coverage, with no evidence of being added to the CISA KEV catalog or other hot lists. Organizations using affected ABB products should prioritize patching to mitigate potential risks.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.91, <= 2.8.0.367CPE matchmatch criteria
cpe:2.3:o:abb:pb610_panel_builder_600_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
8.51%
Probability of exploitation in next 30 days
EPSS Percentile
94.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0851 is in the 95th percentile among its peer group of 552 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

packetstormsecurity.com / files/153396/ABB-IDAL-FTP-Server-Path-Traversal.html
ExploitThird Party AdvisoryVDB Entry
seclists.org / fulldisclosure/2019/Jun/37
ExploitMailing ListThird Party Advisory
search.abb.com / library/Download.aspx
MitigationPatchVendor Advisory
darkmatter.ae / xen1thlabs/abb-idal-ftp-server-path-traversal-vulnerability-xl-19-008
ExploitThird Party Advisory
securityfocus.com / bid/108886
Third Party AdvisoryVDB Entry