Low Voltage DC Power Controllers and Drives with CODESYS RTS

Vulnerabilities in ABB products that could allow attackers to trigger a denial of service or execute arbitrary code. Learn more details on the Q2BSTUDIO website.

martes, 8 de abril de 2025 • 1 min read • Q2BSTUDIO Team

Artificial-Intelligence-

View CSAF

1. EXECUTIVE SUMMARY

  • CVSS v3 8.8
  • ATTENTION: Remotely exploitable/low attack complexity
  • Vendor: ABB
  • Equipment: DCT880 memory unit including ABB Drive Application Builder license (IEC 61131-3), DCT880 memory unit including Energy Optimizer, DCS880 memory unit including ABB Drive Application Builder license (IEC 61131-3), DCS880 memory unit including DEMag, DCS880 memory unit including DCC
  • Vulnerabilities: Improper Input Validation, Out-of-bounds Write, Improper Restriction of Operations within the Bounds of a Memory Buffer

2. RISK EVALUATION

Successful exploitation of these vulnerabilities could allow attackers to trigger a denial-of-service condition or execute arbitrary code through fieldbus interfaces.

3. TECHNICAL DETAILS

3.1 AFFECTED PRODUCTS

ABB reports that the following low voltage DC drive and power controller products contain a vulnerable version of CODESYS Runtime:

  • DCT880 memory unit including ABB Drive Application Builder license (IEC 61131-3): All versions
  • DCT880 memory unit including Energy Optimizer: All versions
  • DCS880 memory unit including ABB Drive Application Builder license (IEC 61131-3): All versions
  • DCS880 memory unit including DEMag: All versions
  • DCS880 memory unit including DCC: All versions

3.2 VULNERABILITY OVERVIEW

3.2.1 IMPROPER INPUT VALIDATION CWE-20

After successful authentication as a user in multiple versions of various CODESYS products, specially crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, which could lead to a denial-of-service condition.

CVE-2023-37559 has been assigned to this vulnerability. A CVSS v3 base score of 6.5 has been calculated; the CVSS vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

More information on the website of Q2BSTUDIO.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.