Junglewise Threat Intelligence

CVE-2019-5459: ABB Ability Camera Connect multiple vulnerabilities in VLC component

CVE-2019-5459 · Severity: high · CVSS 9.8 · Published 2026-05-26

Vendors: ABB.

Executive brief

ABB Ability Camera Connect, a software solution used for managing industrial camera systems, includes an outdated version of the VLC media player. This third-party component contains multiple security flaws that could allow an attacker to crash the system or take full control of the computer running the software. While the risk is lower in isolated industrial networks, a successful exploit could lead to unauthorized access to sensitive operational data or disruption of monitoring services.

Technical details

ABB Ability Camera Connect (versions 1.5.0.14 and below) bundles an outdated version of VLC media player (v2.2.4) which is susceptible to numerous critical vulnerabilities. These include heap-based buffer overflows, integer overflows, and out-of-bounds writes (e.g., CVE-2024-46461, CVE-2023-47359). An attacker can exploit these by providing maliciously crafted media files or network streams (such as MMS), potentially leading to arbitrary code execution with the privileges of the target user or a denial-of-service condition. Additionally, a binary hijacking vulnerability in the VLC uninstaller (CVE-2023-46814) could allow local privilege escalation to SYSTEM. ABB has released version 1.5.0.15 to address these issues by updating the third-party components.

Affected products

  • ABB Ability Camera Connect <=1.5.0.14, 1.5.0.15

CVE identifiers

  • CVE-2019-5459
  • CVE-2023-47359
  • CVE-2019-13602
  • CVE-2018-11529
  • CVE-2017-8311
  • CVE-2017-17670
  • CVE-2017-8312
  • CVE-2019-19721
  • CVE-2017-10699
  • CVE-2019-5460
  • CVE-2017-9301
  • CVE-2023-47360
  • CVE-2019-13615
  • CVE-2022-41325
  • CVE-2019-13962
  • CVE-2017-8313
  • CVE-2023-46814
  • CVE-2017-9300
  • CVE-2020-26664
  • CVE-2019-5439
  • CVE-2017-8310
  • CVE-2024-46461

Timeline

  • 2026-05-26: advisory: CISA Advisory ICSA-26-146-05 published
  • 2026-05-26: patched: ABB released version 1.5.0.15 to address the vulnerabilities

References