The vendor explicitly identifies these products as affected by this CVE.
- ABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3
- ABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3
- Summary
- By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
- Remediation
- Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. The following mitigations are recommended. 3. ARM600 system is by default not dependent on the name service (DNS). If name service is not used in the system, the name service port (TCP/UDP port 53) can be blocked by a firewall. Refer to section General security recommendations for additional advice on how to keep your system secure.
