CVE-2020-24686

HIGHCVSS 7.5/10EPSS 1.42%

Last modified

CVE-2020-24686 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC while this vulnerability is exploited, the PLC will show an error state and refuse connections to Automation Builder. EPSS estimates a 1.42% chance of exploitation in the next 30 days.

Description

The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC while this vulnerability is exploited, the PLC will show an error state and refuse connections to Automation Builder. The execution of the PLC application is not affected by this vulnerability. This issue affects ABB AC500 V2 products with onboard Ethernet.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.42%

69.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AbbPm554 FirmwareAll versions
AbbPm556 FirmwareAll versions
AbbPm564 FirmwareAll versions
AbbPm566 FirmwareAll versions
AbbPm572 FirmwareAll versions
AbbPm573 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-24686?
The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC while this vulnerability is exploited, the PLC will show an error state and refuse connections to Automation Builder. The execution of the PLC application is not affected by this vulnerability. This issue affects ABB AC500 V2 products with onboard Ethernet.
How severe is CVE-2020-24686?
CVE-2020-24686 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.42% probability of exploitation in the next 30 days.
How do I fix CVE-2020-24686?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-24686?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST