QID 590849
Date Published: 2022-07-04
QID 590849: ABB OPC Server for AC 800M Remote Code Execution (RCE) Vulnerability (ICSA-22-074-01)
AFFECTED PRODUCTS
The following versions of OPC Server, a run-time data reader, are affected:
800xA, Control Software for AC 800M:
OPC Server for AC 800M: Versions 5.1.0-x, 5.1.1-x, 6.0.0-1 to 6.0.0-3
Control Builder Safe, 1.x and 2.0 including:
OPC Server for AC 800M: Versions 5.1.1-1 and 6.0.0-1
Compact Product Suite Control and I/O:
OPC Server for AC 800M: Versions 5.1.0-x, 5.1.1-x, 6.0.0-x
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Successful exploitation of this vulnerability could allow a low privileged authenticated user to remotely execute arbitrary code.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-22-074-01 for affected packages and patching details.
Vendor References
- ICSA-22-074-01 -
www.us-cert.gov/ics/advisories/ICSA-22-074-01
CVEs related to QID 590849
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-22-074-01 |
|