Overview
ABB PCU400 contains a vulnerability which can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
Description
The ABB PCU400 application serves as a communication gateway between RTUs that use the IEC-870-5-104 protocol and the SCADA server. The diagnostic web application contains a software flaw which allows an attacker to gain full access on the PCU400 server by sending a specially crafted packet to the X87 web interface on TCP port 8087. Note that this issue affects PCU400 installations running the IEC60870-5-101/104 protocol based on X87. |
Impact
A remote attacker may be able to execute arbitrary code with the privileges of the account running the x87 application. |
Solution
Upgrade or Patch
|
Restrict Access
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This issue was reported by Eyal Udassin and Idan Ofrat of C4 Security.
This document was written by Chris Taschner.
Other Information
CVE IDs: | CVE-2008-2474 |
Severity Metric: | 3.28 |
Date Public: | 2008-09-25 |
Date First Published: | 2008-09-25 |
Date Last Updated: | 2009-03-03 19:47 UTC |
Document Revision: | 22 |