VYPR
High severity7.1NVD Advisory· Published Feb 17, 2020· Updated Jun 17, 2026

CVE-2019-18998

CVE-2019-18998

Description

Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Abb/Asset Suitellm-create
    Range: 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0
  • ABB/Asset Suitev5
    Range: 9.0 to 9.3
  • cpe:2.3:a:hitachienergy:asset_suite:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hitachienergy:asset_suite:*:*:*:*:*:*:*:*range: >=9.0.0,<=9.3.0
    • cpe:2.3:a:hitachienergy:asset_suite:9.6.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.