CVE-2023-0228
published 2023-03-02CVE-2023-0228: Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from…
PriorityP342high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.35%
26.8th percentile
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | symphony_plus_s+_operations | — | — |
| abb | symphony_plus_s+_operations | — | — |
| abb | symphony_plus_s+_operations | 2.x – 2.1 SP2 | — |
| abb | symphony_plus_s+_operations | 3.x – 3.3 SP1 | — |
| abb | symphony_plus_s_+_operations | — | — |
| abb | symphony_plus_s_+_operations | — | — |
| abb | symphony_plus_s_+_operations | — | — |
| abb | symphony_plus_s_+_operations | >= 2.0 < 2.1 | 2.1 |
| abb | symphony_plus_s_+_operations | >= 3.0 < 3.3 | 3.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB Ability Symphony Plus
cisa_ics·2023-03-09·CVSS 8.8
[HIGH] ABB Ability Symphony Plus
ICS Advisory
##
ABB Ability Symphony Plus
Release DateMarch 09, 2023
Alert CodeICSA-23-068-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Low attack complexity
- Vendor: ABB
- Equipment: Ability Symphony Plus
- Vulnerability: Improper Authentication
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an unauthorized client to connect to the S+ Operations servers (human machine interface (HMI) network), to act as a legitimate S+ Operations client.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
ABB reports this vulnerability affects the following Ability Symphony Plus products:
- S+ Operations 3.3 SP2 (part of SPR1 2023.0)
- S+ Operations 3.3 SP1 and earlier 3.x versions
- S+ Operations 2.2
- S+ Operations 2.1 SP2 a
GHSA
GHSA-77h3-ghcp-37gm: Improper Authentication vulnerability in ABB Symphony Plus S+ Operations allows Man in the Middle Attack
ghsa_unreviewed·2023-03-02
CVE-2023-0228 [HIGH] CWE-287 GHSA-77h3-ghcp-37gm: Improper Authentication vulnerability in ABB Symphony Plus S+ Operations allows Man in the Middle Attack
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations allows Man in the Middle Attack.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-02
Published