← Vulnerability feed

Vulnerability record · CVE-2019-7226 · published 27 June 2019

CVE-2019-7226: Abb pb610 panel builder 600 firmware improper authentication vulnerability

Abb · Pb610 Panel Builder 600 Firmware

The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. Specifically, /cgi/loginDefaultUser creates a session in an authenticated state and returns the session ID along with what may be the username and cleartext password of the user. An attacker can then supply an IDALToken value in a cookie, which will allow them to perform privileged operations such as restarting the service with /cgi/restart. A GET request to /cgi/loginDefaultUser may result in "1 #S_OK IDALToken=532c8632b86694f0232a68a0897a145c admin admin" or a similar response.

8.8 CVSS 3.1 High EPSS 5.3% · top 7.7% CWE-287 · Improper authentication
8.8CVSS 3.1 base score, v2 5.8
5.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. Specifically, /cgi/loginDefaultUser creates a session in an authenticated state and returns the session ID along with what may be the username and cleartext password of the user. An attacker can then supply an IDALToken value in a cookie, which will allow them to perform privileged operations such as restarting the service with /cgi/restart. A GET request to /cgi/loginDefaultUser may result in "1 #S_OK IDALToken=532c8632b86694f0232a68a0897a145c admin admin" or a similar response.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-7226 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2019-7228Abb pb610 panel builder 600 firmware vulnerabilityThe ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the use…EPSS 3.7%8.8CVE-2019-7230Abb pb610 panel builder 600 firmware vulnerabilityThe ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%…EPSS 3.7%8.8CVE-2019-7232ABB IDAL HTTP Server Host Header Buffer OverflowThe ABB IDAL HTTP server overflows a stack buffer when a web request carries a Host header of 2047 bytes or more, overwriting a Structured Exception …EPSS 52%analysed7.3CVE-2019-7227Abb pb610 panel builder 600 firmware path traversal vulnerabilityIn the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP serv…EPSS 8.5%5.7CVE-2019-7231Abb pb610 panel builder 600 firmware memory buffer overflow vulnerabilityThe ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This overflow is handled, but ter…EPSS 6.8%7.5CVE-2026-42018JFrog Artifactory improper authentication leaks anonymous tokenJFrog Artifactory can return an internal anonymous-user token to an unauthenticated caller even when anonymous access is disabled. Because the token …KEVEPSS 9.8%analysed9.8CVE-2026-82329JFrog Artifactory improper authentication allows admin takeoverJFrog Artifactory contains an improper authentication weakness (CWE-287) that, under default configuration, may let an unauthenticated attacker with …KEVEPSS 14%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed

Source: NIST National Vulnerability Database (record CVE-2019-7226), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.