1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Remotely exploitable/low attack complexity
- Vendor: ABB
- Equipment: DCT880 memory unit including ABB Drive Application Builder license (IEC 61131-3), DCT880 memory unit including Energy Optimizer, DCS880 memory unit including ABB Drive Application Builder license (IEC 61131-3), DCS880 memory unit including DEMag, DCS880 memory unit including DCC
- Vulnerabilities: Improper Input Validation, Out-of-bounds Write, Improper Restriction of Operations within the Bounds of a Memory Buffer
2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow attackers to trigger a denial-of-service condition or execute arbitrary code through fieldbus interfaces.
3. TECHNICAL DETAILS
3.1 AFFECTED PRODUCTS
ABB reports that the following low voltage DC drive and power controller products contain a vulnerable version of CODESYS Runtime:
- DCT880 memory unit including ABB Drive Application Builder license (IEC 61131-3): All versions
- DCT880 memory unit including Energy Optimizer: All versions
- DCS880 memory unit including ABB Drive Application Builder license (IEC 61131-3): All versions
- DCS880 memory unit including DEMag: All versions
- DCS880 memory unit including DCC: All versions
3.2 VULNERABILITY OVERVIEW
3.2.1 IMPROPER INPUT VALIDATION CWE-20
After successful authentication as a user in multiple versions of various CODESYS products, specially crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, which could lead to a denial-of-service condition.
CVE-2023-37559 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
More information on the website of Q2BSTUDIO.





