VDB
ICSA-23-143-02
ICSA-23-143-02
PUBLISHED
CVSS 7.400000095367432 HIGH
Successful exploitation of these vulnerabilities could allow an attacker to crash the device being accessed or cause a denial-of-service condition.
Risk Scores
CVSS v3.1
7.400000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| RTU500 series CMU Firmware: >=12.0.1|<=12.0.15 | ||
| RTU500 series CMU Firmware: >=12.7.1|<=12.7.6 | ||
| RTU500 series CMU Firmware: >=13.4.1|<=13.4.2 | ||
| RTU500 series CMU Firmware: >=12.6.1|<=12.6.9 | ||
| RTU500 series CMU Firmware: >=12.4.1|<=12.4.12 | ||
| RTU500 series CMU Firmware: >=13.3.1|<=13.3.3 | ||
| RTU500 series CMU Firmware: >=12.2.1|<=12.2.12 | ||
| RTU500 series CMU Firmware: >=13.2.1|<=13.2.6 |
Timeline
- May 5, 2023 CVE Published
- Oct 19, 2023 CVE Updated
References
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2023/icsa-23-143-02.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-143-02 advisory
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 url
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B url
- https://search.abb.com/library/Download.aspx?DocumentID=8DBD000150&LanguageCode=en&DocumentPartId=&Action=Launch fix
- https://search.abb.com/library/Download.aspx?DocumentID=8DBD000153&LanguageCode=en&DocumentPartId=&Action=Launch fix