The vendor explicitly identifies these products as affected by this CVE.
- Lite Panel Pro Version <=1.0.1
- Summary
- The Lite Panel Pro web application does not invalidate active user sessions following a password reset. As a result, sessions established prior to the reset may remain valid, potentially exposing the system to unauthorized access if those session tokens are compromised. Although the session token is time-limited— expiring after 15 minutes by default—a malicious actor who obtains a valid token within this window could potentially have unauthorized access to the system.
- Remediation
- The vulnerabilities are resolved in the following product versions: Lite Panel Pro version 1.1.0 ABB advises users to update their devices to the latest firmware version, following the instructions available here: FW updates - Lite Panel Pro | Lite Panel Pro | ABB Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information
