← Back to home
ICSA-15-069-02  ·  Published 2025-06-06  ·  View on CISA ICS-CERT ↗

ABB HART Device DTM Vulnerability

CVSS 2.1 LOW

CVEs (1)

Remediations

  • Recommended security practices and firewall configurations can help protect a process control network from attacks that originate from outside the network. Process control systems (including the 4-20 mA current loop for connecting field devices) should be physically protected from direct access by unauthorized personnel, have no direct connections to the Internet, and separated from other networks by means of a firewall system that has a minimal number of ports exposed. Process control systems should not be used for Internet surfing, instant messaging, or receiving emails. Portable computers and removable storage media should be carefully scanned for viruses before they are connected to a control system.
  • Using a virus scanner on all Windows-based system nodes, with the latest updates and with on‑access scanning enabled, can help prevent infection by malicious or unwanted software.
  • ABB’s security bulletin titled SECURITY BULLETIN - HART Vulnerability in ABB Third Party Device Type Library, includes patch information regarding this vulnerability. This security bulletin is available at:http://www05.abb.com/global/scot/scot400.nsf/veritydisplay/8b6117ce372491c0c1257dea004c6536/$file/2PAA114210_-_en_SECURITY_BULLETIN_-_HART_Vulnerability_in_ABB_Third_Party_Device_Type_Library.pdf
  • ABB provides Alerts and Notifications of their products on their web site at: http://www.abb.com/cawp/abbzh254/2c9d1261d9fa1dcfc1257950002e4fbf.aspx

Affected Vendors

ABB

Affected Products (8)

ABB · ABB Third-Party Device Type Library <=1.17
ABB · 800xA¾Device Management HART vers:all/*
ABB · Freelance ABB Third-Party HART DTMLibrary <=1.4.178.214
ABB · Freelance 800F vers:all/*
ABB · S Plus Melody ABB Third-Party HART DTMLibrary <=1.4.175.185
ABB · Symphony Plus with Composer Melody vers:all/*
ABB · S+Engineering for Melody vers:all/*
ABB · Composer Field vers:all/*

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more