CVE-2020-24686
The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC while this vulnerability is exploited, the PLC will show an error state and refuse connections to Automation Builder. The execution of the PLC application is not affected by this vulnerability. This issue affects ABB AC500 V2 products with onboard Ethernet.
Published:Feb 26, 2021
Last Modified:Nov 21, 2024
EPS:Feb 26, 2021
EPSS Score:0.00555
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Abb
Product
Pm554
Abb
Pm554
Vendor
Abb
Product
Pm554 Firmware
Abb
Pm554 Firmware
Vendor
Abb
Product
Pm556
Abb
Pm556
Vendor
Abb
Product
Pm556 Firmware
Abb
Pm556 Firmware
Vendor
Abb
Product
Pm564
Abb
Pm564
Vendor
Abb
Product
Pm564 Firmware
Abb
Pm564 Firmware
Vendor
Abb
Product
Pm566
Abb
Pm566
Vendor
Abb
Product
Pm566 Firmware
Abb
Pm566 Firmware
Vendor
Abb
Product
Pm572
Abb
Pm572
Vendor
Abb
Product
Pm572 Firmware
Abb
Pm572 Firmware
Vendor
Abb
Product
Pm573
Abb
Pm573
Vendor
Abb
Product
Pm573 Firmware
Abb
Pm573 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
