PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-42703 ABB CVE debrief

CVE-2022-42703 is a Linux kernel use-after-free in mm/rmap.c related to leaf anon_vma double re-use. In the supplied CISA/ABB advisory, it is mapped to ABB M2M Gateway ARM600 firmware 4.1.2 through 5.0.3 and ABB M2M Gateway SW 5.0.1 through 5.0.3. The advisory indicates the issue could cause a system crash or elevation of privileges, with local exploitation and high privileges required.

Vendor
ABB
Product
ABB M2M Gateway ARM600
CVSS
MEDIUM 4.4
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-07
Original CVE updated
2025-04-07
Advisory published
2025-04-07
Advisory updated
2025-04-07

Who should care

OT/ICS operators using ABB M2M Gateway ARM600 or ABB M2M Gateway SW, especially teams responsible for firmware/software inventory, network segmentation, and access control. Vulnerability management, plant security, and Linux platform administrators supporting these gateways should also review exposure.

Technical summary

The supplied advisory describes a Linux kernel flaw before 5.19.7 in mm/rmap.c involving a use-after-free tied to leaf anon_vma double re-use. The CVSS vector (AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) indicates local access is needed, privileges are high, and the primary impact is availability, with potential privilege escalation noted in the advisory text. CISA’s CSAF mapping identifies ABB M2M Gateway ARM600 firmware versions 4.1.2 through 5.0.3 and ABB M2M Gateway SW 5.0.1 through 5.0.3 as affected.

Defensive priority

Medium

Recommended defensive actions

  • Inventory ABB M2M Gateway ARM600 and ABB M2M Gateway SW deployments and confirm whether any instance falls within the affected version ranges listed in the advisory.
  • Apply ABB/CISA mitigations: avoid exposing the system to the internet, use a private APN where possible, and expose only necessary VPN connectivity if internet access is unavoidable.
  • Use firewall allowlisting and, where appropriate, a DMZ to segregate external connections from the ARM600 environment.
  • Restrict administrative and root access to only what is required, and keep default credentials replaced with strong non-default passwords.
  • Monitor for instability, crashes, or anomalous behavior and maintain verified backups so recovery is possible if availability is affected.
  • Follow ABB product cybersecurity deployment guidance and CISA ICS defense-in-depth recommendations for hardening, patch governance, and supporting workstation hygiene.

Evidence notes

The evidence corpus is the CISA CSAF advisory ICSA-25-105-08 and its linked ABB/CISA references. The advisory explicitly states: "mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double re-use" and maps that issue to ABB M2M Gateway ARM600 firmware versions 4.1.2 <= 5.0.3 and ABB M2M Gateway SW software versions 5.0.1 <= 5.0.3. The supplied CVSS vector (AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H) supports a local, high-privilege attack path with high availability impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-42703 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-42703

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-42703 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-42703

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-08.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://library.e.abb.com/public/0498e4c0babd46aa9243aedd6f99c375/ARM600_user_758861_ENk.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://library.e.abb.com/public/ffab1a14a42646c6adee38fc3de61dad/Arctic_csdepl_758860_ENf.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-08

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.