CVE-2020-24685

An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR LED flashing red), physical access to the PLC is required in order to restart the application. This issue affects: ABB AC500 V2 products with onboard Ethernet version 2.8.4 and prior versions.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:abb:ac500_cpu_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:abb:pm573-eth:2.0:*:*:*:*:*:*:*
cpe:2.3:h:abb:pm583-eth:2.0:*:*:*:*:*:*:*

History

16 Feb 2021, 16:09

Type Values Removed Values Added
CPE cpe:2.3:o:abb:ac500_cpu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:pm583-eth:2.0:*:*:*:*:*:*:*
cpe:2.3:h:abb:pm573-eth:2.0:*:*:*:*:*:*:*
References (CONFIRM) https://search.abb.com/library/Download.aspx?DocumentID=3ADR010667&LanguageCode=en&DocumentPartId=&Action=Launch - (CONFIRM) https://search.abb.com/library/Download.aspx?DocumentID=3ADR010667&LanguageCode=en&DocumentPartId=&Action=Launch - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 8.6
CWE CWE-770

09 Feb 2021, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-09 04:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-24685

Mitre link : CVE-2020-24685

CVE.ORG link : CVE-2020-24685


JSON object : View

Products Affected

abb

  • pm573-eth
  • pm583-eth
  • ac500_cpu_firmware
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-789

Memory Allocation with Excessive Size Value