CVE-2019-18998: Hitachienergy Asset Suite

High severity, CVSS 7.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.

Affected products

  • Hitachienergy Asset Suite: from 9.0.0, up to and including 9.3.0; from 9.4, before 9.4.2.6 (fixed in 9.4.2.6); from 9.5.0, before 9.5.3.2 (fixed in 9.5.3.2); version 9.6.0 only

Published 2020-02-17. Last modified 2026-06-17.