• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

High-Risk Vulnerability Found in ABB’s Flow Computers

You are here: Home / General Cyber Security News / High-Risk Vulnerability Found in ABB’s Flow Computers
November 9, 2022

A path-traversal vulnerability has been uncovered in ABB Totalflow move desktops and controllers that could lead to code injection and arbitrary code execution (ACE).

The high-risk vulnerability (tracked CVE-2022-0902) has a CVSS v3 of 8.1 and impacted quite a few ABB G5 solutions. It has been discovered by security authorities at Staff82, Claroty’s analysis arm.

“Attackers can exploit this flaw to get root access on an ABB stream personal computer, examine and publish information, and remotely execute code,” the company wrote in an advisory released on Tuesday.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


In specific, attackers could try out to exploit the vulnerability by building a specially crafted concept and sending it to an impacted system node.

The procedure would need the attacker to have access to the program network, both directly or by way of a wrongly configured or breached firewall. They could also install malicious software package on a technique node or infect the network itself with destructive software program.

Team82 has stated it disclosed the vulnerability to ABB, which promptly introduced a firmware update that resolves the vulnerability in many products versions.

“The update removes the vulnerability by modifying the way that the Totalflow protocol validates messages and verifies input knowledge,” ABB defined.

The advisory also endorses network segmentation as a mitigation tactic.

“To mitigate this vulnerability, the ABB product ought to only be related to a network section that restricts entry to licensed people,” reads the ABB complex compose-up. “The vulnerability is only uncovered when the attacker has obtain to the network exactly where the ABB gadget is managing Totalflow TCP protocol.”

More mitigation strategies incorporate installing bodily controls so no unauthorized personnel can access units and networks and scanning all facts imported into environments in advance of use to detect probable malware bacterial infections.

A entire list of security tips, along with particulars about CVE-2022-0902, is available in the initial textual content of the ABB advisory.

The mitigation arrives months just after the Cybersecurity and Infrastructure Security Company (CISA) issued a new report outlining cybersecurity efficiency plans (CPGs) for critical infrastructure sectors.


Some elements of this post are sourced from:
www.infosecurity-journal.com

Previous Post: «Cyber Security News Malicious Package on PyPI Hides Behind Image Files, Spreads Via GitHub
Next Post: New UEFI Firmware Flaws Reported in Several Lenovo Notebook Models new uefi firmware flaws reported in several lenovo notebook models»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.