Description
Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affects AC500 V2: from 2.0.0 before 2.8.6.

Published: 2023-03-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Use the communication protocol "Tcp/Ip" instead of "ABB Tcp/Ip Level 2" (i.e. Port 1201 instead of 1200) for the connection between engineering software and PLC. This protocol/port is not affected by the DoS impact of the vulnerability.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-42609 Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affects AC500 V2: from 2.0.0 before 2.8.6.
History

Tue, 11 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Abb Ac500 Cpu Firmware Pm5630-2eth Pm5650-2eth Pm5670-2eth Pm5675-2eth Pm571-eth-v14x Pm571-v14x Pm572 Pm573-eth Pm581-eth-v14x Pm581-v14x Pm582 Pm582-arcnet Pm582-eth Pm582-v14x Pm583-eth Pm585-eth Pm585-mc-kit Pm590-arcnet-v14x Pm590-eth Pm590-eth-v14x Pm590-mc-kit Pm590-v14x Pm591-2eth Pm591-arcnet-v14x Pm591-eth Pm591-eth-v14x Pm591-v14x Pm592-eth Pm595-4eth-f
cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2025-02-11T18:40:07.850Z

Reserved: 2022-09-13T05:57:45.421Z

Link: CVE-2022-3192

cve-icon Vulnrichment

Updated: 2024-08-03T01:00:10.643Z

cve-icon NVD

Status : Modified

Published: 2023-03-31T17:15:06.427

Modified: 2024-11-21T07:19:00.950

Link: CVE-2022-3192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses