IM
IronMonkey Threat Research

CVE-2024-3036 MEDIUM

Published: 2024-06-21 | Last Modified: 2025-12-19 | Status: Analyzed

Description

Improper Input Validation vulnerability in ABB 800xA Base. An attacker who successfully exploited this vulnerability could cause services to crash by sending specifically crafted messages. This issue affects 800xA Base: from 6.0.0 through 6.1.1-2.

Additional Descriptions (1)

Vulnerabilidad de validación de entrada incorrecta en ABB 800xA Base. Un atacante que aprovechara con éxito esta vulnerabilidad podría provocar que los servicios fallaran al enviar mensajes específicamente diseñados. Este problema afecta a 800xA Base: desde 6.0.0 hasta 6.1.1-2.

CVSS Metrics

Base Score: 5.7 (MEDIUM)

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorADJACENT_NETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 2.1

Impact Score: 3.6

Base Score: 6.9 (MEDIUM)

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:A/V:D/RE:M/U:X

Attack VectorADJACENT
Attack ComplexityLOW
Attack RequirementsNONE
Privileges RequiredLOW
User InteractionNONE
Vulnerability ConfidentialityNONE
Vulnerability IntegrityNONE
Vulnerability AvailabilityHIGH
Subsequent ConfidentialityNONE
Subsequent IntegrityNONE
Subsequent AvailabilityNONE

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-1284

Affected Products

Vendor Product Version Update Type
abb 800xa_base_system * <built-in method update of dict object at 0x7b06ff12b500> Application
abb 800xa_base_system * <built-in method update of dict object at 0x7b06ff12a340> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:abb:800xa_base_system:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:abb:800xa_base_system:*:*:*:*:*:*:*:*
Notification
Message here