CVE-2020-24685

An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR LED flashing red), physical access to the PLC is required in order to restart the application. This issue affects: ABB AC500 V2 products with onboard Ethernet version 2.8.4 and prior versions.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:abb:ac500_cpu_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:abb:pm573-eth:2.0:*:*:*:*:*:*:*
cpe:2.3:h:abb:pm583-eth:2.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:15

Type Values Removed Values Added
References () https://search.abb.com/library/Download.aspx?DocumentID=3ADR010667&LanguageCode=en&DocumentPartId=&Action=Launch - Patch, Vendor Advisory () https://search.abb.com/library/Download.aspx?DocumentID=3ADR010667&LanguageCode=en&DocumentPartId=&Action=Launch - Patch, Vendor Advisory

Information

Published : 2021-02-09 04:15

Updated : 2024-11-21 05:15


NVD link : CVE-2020-24685

Mitre link : CVE-2020-24685

CVE.ORG link : CVE-2020-24685


JSON object : View

Products Affected

abb

  • pm573-eth
  • ac500_cpu_firmware
  • pm583-eth
CWE
CWE-789

Memory Allocation with Excessive Size Value

CWE-770

Allocation of Resources Without Limits or Throttling