CVE-2020-24685
AC500 V2 unauthenticated crafter packet vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR LED flashing red), physical access to the PLC is required in order to restart the application. This issue affects: ABB AC500 V2 products with onboard Ethernet version 2.8.4 and prior versions.
Un paquete no autenticado especialmente diseñado y enviado por un atacante a través de la red causará una vulnerabilidad de denegación de servicio (DoS). Una vulnerabilidad permite a un atacante detener el PLC. Después de detenerse (LED ERR parpadeando en rojo), es requerido acceso físico al PLC para reiniciar la aplicación. Este problema afecta a: Productos ABB AC500 V2 con Ethernet integrado versión 2.8.4 d y anteriores
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-08-26 CVE Reserved
- 2021-02-09 CVE Published
- 2023-10-25 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-770: Allocation of Resources Without Limits or Throttling
- CWE-789: Memory Allocation with Excessive Size Value
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://search.abb.com/library/Download.aspx?DocumentID=3ADR010667&LanguageCode=en&DocumentPartId=&Action=Launch | 2021-02-16 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Abb Search vendor "Abb" | Ac500 Cpu Firmware Search vendor "Abb" for product "Ac500 Cpu Firmware" | < 2.8.5 Search vendor "Abb" for product "Ac500 Cpu Firmware" and version " < 2.8.5" | - |
Affected
| in | Abb Search vendor "Abb" | Pm573-eth Search vendor "Abb" for product "Pm573-eth" | 2.0 Search vendor "Abb" for product "Pm573-eth" and version "2.0" | - |
Safe
|
Abb Search vendor "Abb" | Ac500 Cpu Firmware Search vendor "Abb" for product "Ac500 Cpu Firmware" | < 2.8.5 Search vendor "Abb" for product "Ac500 Cpu Firmware" and version " < 2.8.5" | - |
Affected
| in | Abb Search vendor "Abb" | Pm583-eth Search vendor "Abb" for product "Pm583-eth" | 2.0 Search vendor "Abb" for product "Pm583-eth" and version "2.0" | - |
Safe
|