The vendor explicitly identifies these products as affected by this CVE.
- ANC Version <=1.1.4
- ANC-L version <=1.1.4
- ANC-mini version <=1.1.4
- Summary
- A use of GET request method with sensitive query strings vulnerability allows an attacker to view plaintext password, if the attacker is able to read the GET requests to those services. This problem is resolved in software version 1.1.5, apply the update at earliest convenience.
- Remediation
- All web HMI related problems (CVE-2024-47784, CVE-2024-9876, CVE-2024-9877) are corrected in the product version 1.1.5. ABB recommends that customers apply the update at earliest convenience. The process to identify the installed product version and process to install updates is described in the user manual.
