CVE-2024-48851

7.2

ABB · FLXEON

ABB FLXEON is susceptible to improper input validation, which can lead to remote code execution by a privileged attacker.

Executive summary

An improper input validation vulnerability in ABB FLXEON allows an authenticated remote attacker to achieve remote code execution on the affected system.

Vulnerability

This vulnerability, identified as CWE-1287, involves improper validation of input types within the FLXEON software. The vulnerability requires high privileges (PR:H) to exploit, allowing an authenticated user to trigger remote code execution.

Business impact

The ability to execute arbitrary code remotely poses a severe risk to operational integrity, potentially allowing an attacker to gain full control over the affected ABB FLXEON system. With a CVSS score of 7.2, this vulnerability is classified as High severity, indicating a significant threat to system confidentiality, integrity, and availability. Compromise of such industrial control components can lead to unauthorized system manipulation and potential disruption of critical operational processes.

Remediation

Immediate Action: Update the ABB FLXEON software to the latest version provided by the vendor to resolve the input validation flaws. Please refer to the official ABB security advisory for specific patch installation instructions.

Proactive Monitoring: Monitor system logs for unauthorized configuration changes, anomalous administrative activity, or unexpected process execution patterns that may indicate an exploitation attempt.

Compensating Controls: Restrict administrative access to the FLXEON interface to trusted, secure workstations and ensure that network-level access is limited to authorized personnel only.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

Given the potential for remote code execution, this vulnerability represents a significant security risk to environments utilizing ABB FLXEON. Administrators should prioritize identifying all instances of the affected software within their infrastructure and apply the vendor-supplied updates immediately. Ensuring that access controls are strictly enforced is essential to mitigating the risk while the update process is underway.

More ABB CVEs

Sources

Originally found and disclosed by ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure., per the CVE Program record.