The ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This overflow is handled, but terminates the process. An authenticated attacker can send a FTP command string of 472 bytes or more to overflow a buffer, causing an exception that terminates the server.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7231
Reference (s):
- BID:108886
- URL: http://www.securityfocus.com/bid/108886
- https://search.abb.com/library/Download.aspx?DocumentID=3ADR010377&LanguageCode=en&DocumentPartId=&Action=Launch
- FULLDISC:20190620 XL-19-007 – ABB IDAL FTP Server Buffer Overflow Vulnerability
- URL: http://seclists.org/fulldisclosure/2019/Jun/35

