The vendor explicitly identifies these products as affected by this CVE.
- ABB Ability™ Symphony® Plus S+ Engineering 2.2
- ABB Ability™ Symphony® Plus S+ Engineering 2.3
- ABB Ability™ Symphony® Plus S+ Engineering 2.3 RU1
- ABB Ability™ Symphony® Plus S+ Engineering 2.3 RU2
- ABB Ability™ Symphony® Plus S+ Engineering 2.3 RU3
- ABB Ability™ Symphony® Plus S+ Engineering 2.4
- ABB Ability™ Symphony® Plus S+ Engineering 2.4 SP1
- ABB Ability™ Symphony® Plus S+ Engineering 2.4 SP2
- Summary
- An attacker running as an authenticated PostgreSQL user can provide crafted data and trigger the integer overflow due to such missing overflow check. This can enable the execution of arbitrary code in the system.
- Remediation
- ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - Systems using S+ Engineering 2.2 through 2.4 SP2 should upgrade to S+ Engineering 2.4 SP2 RU1 (re-leased in December 2024) or later. - End users who are unable to install one of these updates should immediately look to implement the Mitigation and Workarounds listed below as this will restrict or prevent an attacker’s ability to com-promise the system. ABB recommends that customers apply the update at the earliest convenience.
