ABB ACS880 Drives Containing CODESYS RTS
ABB ACS880 drives containing vulnerable CODESYS Runtime System versions contain multiple input validation and buffer overflow flaws (CWE-20, CWE-787, CWE-119) in the drive firmware. An attacker with engineering credentials and network access to the drive's programming interface could upload and execute arbitrary code or trigger denial of service. The vulnerability stems from insufficient validation of IEC online programming communication. ABB has released firmware updates that disable IEC online programming by default and fix the underlying input validation issues. For products without patches available (APCLX, ATBLX), the workaround is to manually disable file download capability via parameter 196.102.
- Network access to the ACS880 drive's engineering communication port
- Valid CODESYS engineering tool credentials or programming software access
- IEC online programming enabled (default disabled in patched versions)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/c008ccd1-f324-4644-8e45-86a258293ded