ABB has an update available to handle use of insufficiently random values and a cross-site request forgery (CSRF) in its Pulsar Plus Controller, according to a report with CISA.

Successful exploitation of these remotely exploitable vulnerabilities, discovered by Vlad Ionescu of Facebook Red Team X, could allow an attacker to take control of the product or execute arbitrary code.

The following versions of ABB Pulsar Plus Controller, suffer from the vulnerabilities:

  • ABB Infinity DC Power Plant – H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415
  • ABB Pulsar Plus System Controller – NE843_S – comcode 150042936

In one issue, there are several fields in the web pages where a user can enter arbitrary text, such as a description of an alarm or a rectifier. These represent a cross site scripting vulnerability where JavaScript code can be entered as the description with the potential of causing system interactions unknown to the user. These issues were remediated by adding a check of every field update to reject suspicious entries.

Schneider Bold

CVE-2022-1607 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 4.6.

In addition, every interaction with the web server requires a Session ID assigned to the session after a successful login. The reported vulnerability is the Session IDs were too short (16 bits), too predictable (IDs simply incremented), and were plainly visible in the URLs of the web pages. These issues were remediated by rewriting the web server to follow recommended best practices.

CVE-2022-26080 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 6.3.

The product sees use in the chemical, critical manufacturing, dams, energy, food and agriculture, and water and wastewater sectors, and on a global basis.

No known public exploits specifically target these vulnerabilities. However, an attacker could leverage these low complexity vulnerabilities.

ABB has an available update resolving a privately reported vulnerability in the product versions listed above. The update is version number 5.0.0 for the application and 5.0.0 for web pages. These updates have been distributed through the appropriate product support channels with affected users.

ABB recommends users ensure the firewall protection is properly configured.

A workaround suggested by ABB is to use the controller’s Read/Write Enable/Disable feature for a network port (NET1,WRE=0).

The controller can disable all writes over the network port. The factory default is to have the write capability enabled. However, some users may not want settings to be remotely changed once systems are set. This feature, when set to “Disable,” will allow no changes to be accepted. Once set, it can only be changed locally through the front panel.

Although these workarounds will not correct the underlying vulnerability, they can help block known attack vectors.

ISSSource

Pin It on Pinterest

Share This