AC 800PEC, AC 800PEC ARM, AC 800PEC Tool, Control Terminal (xCT) and AC 800PEC Tool Cheetah Impacted by multiple vulnerabilities in Wibu CodeMeter
Multiple vulnerabilities in the embedded Wibu CodeMeter license manager affect ABB control platform tools and engineering software. The vulnerabilities allow remote attackers to delete arbitrary files with system privileges, modify configuration data in Server.ini, crash the CodeMeter service and disclose sensitive process memory information, or access license information. Exploitation requires the CodeMeter network server functionality to be enabled (which it may be by default or from previous configuration). Affected versions: AC 800PEC before 5.4.5.2, AC 800PEC ARM all versions, AC 800PEC Tool all versions, AC 800PEC Tool Cheetah all versions, and Control Terminal (xCT) all versions.
- Network access to CodeMeter network server port (if enabled)
- CodeMeter network server functionality must be enabled on the target system
Patching may require device reboot — plan for process interruption
/api/v1/advisories/73816373-4173-498d-a9ef-38cc0f117e23Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.