CVE-2024-3036
published 2024-06-21CVE-2024-3036: Improper Input Validation vulnerability in ABB 800xA Base. An attacker who successfully exploited this vulnerability could cause services to crash by sending…
PriorityP423medium5.7CVSS 3.1
AVAACLPRLUINSUCNINAH
EPSS
0.26%
17.5th percentile
Improper Input Validation vulnerability in ABB 800xA Base.
An attacker who successfully exploited this
vulnerability could cause services to crash by sending specifically crafted messages.
This issue affects 800xA Base: from 6.0.0 through 6.1.1-2.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | 800xa_base | 6.0.0 – 6.1.1-2 | — |
| abb | 800xa_base_system | 6.0 – 6.0.3-9 | — |
| abb | 800xa_base_system | 6.1 – 6.1.1-2 | — |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.9MEDIUMCVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:D/RE:M/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-82h3-85h2-hh9r: Improper Input Validation vulnerability in ABB 800xA Base
ghsa_unreviewed·2024-06-21
CVE-2024-3036 [MEDIUM] CWE-1284 GHSA-82h3-85h2-hh9r: Improper Input Validation vulnerability in ABB 800xA Base
Improper Input Validation vulnerability in ABB 800xA Base.
An attacker who successfully exploited this
vulnerability could cause services to crash by sending specifically crafted messages.
This issue affects 800xA Base: from 6.0.0 through 6.1.1-2.
CISA ICS
ABB Ability System 800xA
cisa_ics·2024-06-25·CVSS 6.9
[MEDIUM] ABB Ability System 800xA
ICS Advisory
##
ABB Ability System 800xA
Release DateJune 25, 2024
Alert CodeICSA-24-177-01
Related topics:
Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 6.9
- ATTENTION: Low attack complexity
- Vendor: ABB
- Equipment: 800xA Base
- Vulnerabilities: Improper Input Validation
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause services to crash and restart.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
ABB reports that the vulnerability only affects 800xA services in PC based client/server nodes. Controllers are not affected by this vulnerability:
- ABB 800xA Base: versions 6.1.1-2 and prior
## 3.2 Vulnerability Overview
## 3.2.1 Improper Input Validation CWE-20
An attacker who successfull
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-21
Published