CVE-2020-24685
Last modified
CVE-2020-24685 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. EPSS estimates a 1.61% chance of exploitation in the next 30 days.
Description
An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR LED flashing red), physical access to the PLC is required in order to restart the application. This issue affects: ABB AC500 V2 products with onboard Ethernet version 2.8.4 and prior versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Abb | Ac500 Cpu Firmware | < 2.8.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-24685?
How severe is CVE-2020-24685?
How do I fix CVE-2020-24685?
Are you affected by CVE-2020-24685?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
