CVE-2022-0947 – Arctic Wireless Gateway Firewall vulnerability
https://notcve.org/view.php?id=CVE-2022-0947
A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration. Una vulnerabilidad en la serie ABB ARG600 Wireless Gateway que podría permitir a un atacante explotar la vulnerabilidad al conectarse remotamente a la puerta de enlace del puerto serie, y/o al convertidor de protocolo, dependiendo de la configuración • https://search.abb.com/library/Download.aspx?DocumentID=2NGA001253&LanguageCode=en&DocumentPartId=&Action=Launch • CWE-665: Improper Initialization •
CVE-2022-28613 – Specially Crafted Modbus TCP Packet Vulnerability in RTU500 series
https://notcve.org/view.php?id=CVE-2022-28613
A vulnerability in the HCI Modbus TCP COMPONENT of Hitachi Energy RTU500 series CMU Firmware that is caused by the validation error in the length information carried in MBAP header allows an ATTACKER to reboot the device by sending a special crafted message. This issue affects: Hitachi Energy RTU500 series CMU Firmware 12.0.*; 12.2.*; 12.4.*; 12.6.*; 12.7.*; 13.2.*. Una vulnerabilidad en el COMPONENTE HCI Modbus TCP del firmware de la CMU de la serie RTU500 de Hitachi Energy, causada por un error de comprobación en la información de longitud que se transmite en el encabezado MBAP, permite a un ATACANTE reiniciar el dispositivo mediante el envío de un mensaje especialmente diseñado. Este problema afecta a: Hitachi Energy RTU500 series CMU Firmware versiones 12.0.*; 12.2.*; 12.4.*; 12.6.*; 12.7.*; 13.2.* A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500 CMU to reboot. • https://search.abb.com/library/Download.aspx?DocumentID=8DBD000103&LanguageCode=en&DocumentPartId=&Action=Launch https://publisher.hitachienergy.com/preview?DocumentID=8DBD000103&LanguageCode=en&DocumentPartId=&Action=Launch • CWE-20: Improper Input Validation CWE-1284: Improper Validation of Specified Quantity in Input •
CVE-2021-22277 – AC 800M MMS - Denial of Service vulnerability in MMS communication
https://notcve.org/view.php?id=CVE-2021-22277
Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service. Una vulnerabilidad de comprobación de entrada inapropiada en ABB 800xA, Software de control para AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl permite a un atacante causar la denegación de servicio • https://search.abb.com/library/Download.aspx?DocumentID=7PAA001499&LanguageCode=en&DocumentPartId=&Action=Launch • CWE-20: Improper Input Validation •
CVE-2021-22284 – SECURITY - OPC Server for AC 800M - Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-22284
Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the node running the AC800M OPC Server. Una vulnerabilidad de Asignación de Permisos Incorrecta para Recursos Críticos en el Servidor OPC para AC 800M permite a un atacante ejecutar código arbitrario en el nodo que ejecuta el Servidor OPC AC800M • https://search.abb.com/library/Download.aspx?DocumentID=7PAA000908&LanguageCode=en&DocumentPartId=&Action=Launch • CWE-732: Incorrect Permission Assignment for Critical Resource •
CVE-2021-22285 – SECURITY – Denial of Service Vulnerabilities in SPIET800 INFI-Net to Ethernet Transfer module and PNI800 S+ Ethernet communication interface module
https://notcve.org/view.php?id=CVE-2021-22285
Improper Handling of Exceptional Conditions, Improper Check for Unusual or Exceptional Conditions vulnerability in the ABB SPIET800 and PNI800 module that allows an attacker to cause the denial of service or make the module unresponsive. Una vulnerabilidad de Manejo Inapropiado de Condiciones Excepcionales, Comprobación Inapropiada de Condiciones Inusuales o Excepcionales en el módulo ABB SPIET800 y PNI800 que permite a un atacante causar la denegación de servicio o causar que el módulo no responda • https://search.abb.com/library/Download.aspx?DocumentID=7PAA001353&LanguageCode=en&DocumentPartId=&Action=Launch • CWE-754: Improper Check for Unusual or Exceptional Conditions CWE-755: Improper Handling of Exceptional Conditions •