QID 591342

Date Published: 2023-02-10

QID 591342: ABB Arctic Wireless Gateway Firewall Vulnerability (2NGA001253)

AFFECTED PRODUCTS
ARG600A1220NA, ARG600A1230NA, ARG600A1240NA, ARG600A1260NA, ARG600A2622NA, ARG600A2625NA: from firmware version 2.4.0 up to firmware version 3.4.10
ARP600A2200NA, ARP600A2220NA, ARP600A2250NA, ARP600A2260NA, ARP600A2651NA, ARP600A2560NA: from firmware version 2.4.0 up to firmware version 3.4.10
ARR600A3201NA, ARR600A3202NA, ARR600A3221NA, ARR600A3222NA, ARR600A3251NA, ARR600A3252NA, ARR600A3261NA, ARR600A3262NA: from firmware version 2.4.0 up to firmware version 3.4.10
ARC600A2325NA, ARC600A2323NA, ARC600A2324NA: from firmware version 2.4.0 up to firmware version 3.4.10

QID Detection Logic:
This QID checks for the Vulnerable version of Omron NJ/NX-series Machine Automation Controllers using passive scanning

An attacker could try to exploit the vulnerability by creating a specially crafted message and sending the message to an affected system node. Alternatively, the attacker could run a dictionary attack against the WHMI or CLI login for trying to get access to the device. The exploit would require that the attacker has access to the system network, by connecting to the network either directly or through a public IP address that the device may have.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution

    Customers are advised to refer to ABB MITIGATIONS section 2NGA001253 for affected packages and patching details.

    CVEs related to QID 591342

    Software Advisories
    Advisory ID Software Component Link
    2NGA001253 URL Logo library.e.abb.com/public/f125fbed58594e6d9e1830e30ee3010d/2NGA001253%20Cyber%20Security%20Advisory%20-%20Arctic%20wireless%20GW%20%20Firewall%20rev%20B%20JUN-20-2022.pdf