Lucene search

K
cve[email protected]CVE-2020-24686
HistoryFeb 26, 2021 - 4:15 p.m.

CVE-2020-24686

2021-02-2616:15:12
CWE-400
web.nvd.nist.gov
20
cve-2020-24686
abb ac500 v2
web visualization
remote visibility
login errors
plc
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.1%

The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC while this vulnerability is exploited, the PLC will show an error state and refuse connections to Automation Builder. The execution of the PLC application is not affected by this vulnerability. This issue affects ABB AC500 V2 products with onboard Ethernet.

Affected configurations

NVD
Node
abbpm554Match-
AND
abbpm554_firmwareMatch-
Node
abbpm556Match-
AND
abbpm556_firmwareMatch-
Node
abbpm564Match-
AND
abbpm564_firmwareMatch-
Node
abbpm566Match-
AND
abbpm566_firmwareMatch-
Node
abbpm572Match-
AND
abbpm572_firmwareMatch-
Node
abbpm573Match-
AND
abbpm573_firmwareMatch-

CNA Affected

[
  {
    "product": "AC500 V2 products with onboard Ethernet",
    "vendor": "ABB",
    "versions": [
      {
        "status": "affected",
        "version": "All"
      }
    ]
  }
]

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

47.1%

Related for CVE-2020-24686