Learn about CVE-2020-24685 affecting ABB AC500 V2 products with onboard Ethernet. Discover the impact, technical details, and mitigation steps for this high-severity vulnerability.
An unauthenticated specially crafted packet sent by an attacker over the network can lead to a denial-of-service vulnerability affecting ABB AC500 V2 products with onboard Ethernet version 2.8.4 and prior versions.
Understanding CVE-2020-24685
This CVE involves a vulnerability in ABB AC500 V2 products that allows an attacker to disrupt the Programmable Logic Controller (PLC) through a network-based attack.
What is CVE-2020-24685?
The vulnerability enables an attacker to halt the PLC remotely, requiring physical access to restart the application, impacting the availability of the system.
The Impact of CVE-2020-24685
Technical Details of CVE-2020-24685
This section provides detailed technical insights into the vulnerability.
Vulnerability Description
The flaw allows an attacker to send a specially crafted packet over the network, triggering a denial-of-service condition that stops the PLC, necessitating physical access for recovery.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited by sending a malicious packet over the network, causing the PLC to cease functioning until physically restarted.
Mitigation and Prevention
Protecting systems from CVE-2020-24685 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates