Junglewise Threat Intelligence

CVE-2023-45231: ABB B&R PCs multiple vulnerabilities in UEFI PXE stack

CVE-2023-45231 · Severity: high · CVSS 8.3 · Published 2026-05-21

Vendors: ABB.

Executive brief

ABB B&R industrial PCs are affected by multiple vulnerabilities in their UEFI firmware's network boot component. These PCs are used in critical infrastructure and energy sectors to control and monitor industrial processes. A successful exploit could allow an attacker on the local network to take control of the device, cause it to crash, or intercept sensitive data during the boot process.

Technical details

The vulnerabilities (collectively known as PixieFail) reside in the EDK2 Network Package used within the UEFI firmware of various ABB B&R industrial PCs. The flaws include out-of-bounds reads, buffer overflows, and infinite loops within the Preboot eXecution Environment (PXE) stack, specifically affecting DHCPv6 and IPv6 Neighbor Discovery protocols. An attacker on the same local network segment can exploit these by sending specially crafted network packets during the PXE boot process. This can result in remote code execution, denial-of-service, or DNS cache poisoning. Patches are available for most models, and users are advised to disable PXE boot in UEFI settings if it is not required.

Affected products

  • ABB APC4100 <1.09
  • ABB APC910 <=1.25
  • ABB C80 <1.14
  • ABB MPC3100 <1.24
  • ABB PPC1200 <1.14
  • ABB PPC900 <2.16
  • ABB APC2200 <1.35
  • ABB PPC2200 <1.35
  • ABB APC3100 <1.45
  • ABB PPC3100 <1.45

CVE identifiers

  • CVE-2023-45231
  • CVE-2023-45233
  • CVE-2023-45235
  • CVE-2023-45230
  • CVE-2023-45237
  • CVE-2023-45234
  • CVE-2023-45232
  • CVE-2023-45236
  • CVE-2023-45229

Timeline

  • 2026-05-21: advisory: CISA published advisory ICSA-26-141-02

References