The vendor explicitly identifies these products as affected by this CVE.
- ANC Version <=1.1.4
- ANC-L version <=1.1.4
- ANC-mini version <=1.1.4
- Summary
- A non-administrative user could gain access to an admin page where they could perform all actions which should be restricted only to an admin user. The vulnerability was due to improper validation in the web HMI server. This problem is resolved in software version 1.1.5, apply the update at earliest convenience.
- Remediation
- All web HMI related problems (CVE-2024-47784, CVE-2024-9876, CVE-2024-9877) are corrected in the product version 1.1.5. ABB recommends that customers apply the update at earliest convenience. The process to identify the installed product version and process to install updates is described in the user manual.
