Executive brief
ABB Ability Symphony Plus Engineering, a suite used for managing industrial control systems in sectors like energy and water, is affected by several vulnerabilities in its bundled PostgreSQL database. If an attacker gains access to the engineering network, they could execute unauthorized code, potentially leading to a full system compromise or disruption of critical infrastructure operations. Owners of affected systems should upgrade to the latest software version to secure their environments.
Technical details
ABB Ability Symphony Plus Engineering versions 2.2 through 2.4 SP2 are affected by multiple vulnerabilities inherited from PostgreSQL (version 13.11 and earlier). These include an integer overflow (CVE-2023-5869), SQL injection via extension scripts (CVE-2023-39417), and a TOCTOU race condition (CVE-2024-7348). An attacker with network access to the S+ Client Server network and low-privileged database credentials can exploit these flaws to execute arbitrary code or SQL functions with elevated privileges. The vulnerabilities effectively allow for a complete compromise of the engineering workstation's database and potentially the host system. ABB has released S+ Engineering 2.4 SP2 RU1 to address these issues by updating the underlying database components.
Affected products
- ABB Ability Symphony Plus Engineering 2.2, 2.3, 2.3_RU1, 2.3_RU2, 2.3_RU3, 2.4, 2.4_SP1, 2.4_SP2, 2.4_SP2_RU1
CVE identifiers
- CVE-2024-0985
- CVE-2023-5869
- CVE-2023-39417
- CVE-2024-7348
Timeline
- 2024-12-01: patched: S+ Engineering 2.4 SP2 RU1 re-released with fixes
- 2026-04-30: advisory: CISA and ABB publish official advisory ICSA-26-120-06