NEWS DESK

Vulnerabilities discovered by Positive Technologies in ABB controllers have been fixed

ABB thanked Natalya Tlyapova and Denis Goryushev for discovering two vulnerabilities in its Freelance AC 900F and AC 700F controllers. These devices are used in the metal and chemical industry. The vendor was notified of the threat in line with the responsible disclosure policy and released software patches.

The AC 900F and AC 700F controllers are used in distributed control systems (DCS) of industrial plants to automate their continuous production processes. ABB is leading in the global DCS market, with a market share of 20%.

Vulnerabilities CVE-2023-0425 and CVE-2023-0426 both received a CVSS v3.1 score of 8.6, which means high severity.

According to the application analysts at Positive Technologies who discovered the vulnerabilities, exploitation of these security flaws can allow attackers to shut down controllers, disrupting production processes. In addition, sending a specially crafted package could enable remote code execution attacks aimed at hijacking the devices.

ABB recommends installing updates Freelance 2016 SP1 RU06, Freelance 2019 SP1 RU02, and Freelance 2019 SP1 FP1 RU03 as soon as possible. To mitigate the threat, users can also take actions described in the security advisory.

Positive Technologies suggests using PT Industrial Security Incident Manager, an in-depth industrial traffic analysis system, for detecting attempts to exploit ICS vulnerabilities. PT ISIM recognizes communication protocols of ABB Freelance controllers, analyzes commands, and informs the security team about suspicious events and incidents.

PR News Desk

PR News Desk

Disclaimer: This press release, supplied by an external third-party provider, is not under the control of this website. The information is provided 'as is' and 'as available,' and has not been edited by this website. Neither this website nor its affiliates can guarantee the accuracy of the content or endorse the opinions expressed in this press release. This press release is intended solely to inform and educate. It does not offer tax, legal, or investment advice or provide any opinion on the suitability, value, or profitability of any specific security, portfolio, or investment strategy. Neither this website nor its affiliates will be held liable for any errors or inaccuracies in the content, nor for any actions you may take based on this information. Using the information in this press release, you agree to do so at your own risk. This website, its parent company, affiliates, directors, officers, employees, agents, advertisers, and content providers, shall not be liable for any direct, indirect, consequential, special, incidental, punitive, or exemplary damages, including but not limited to lost profits, savings, or revenues, whether arising from negligence, tort, contract, or any other legal theory, even if advised of the possibility of such damages or if they could have been reasonably foreseen. Send press releases to press@menews247
Follow Me:

Related Posts