PatchSiren cyber security CVE debrief
CVE-2023-5869 ABB CVE debrief
CVE-2023-5869 affects ABB Ability Symphony Plus S+ Engineering and is rated high severity (CVSS 8.8). According to the advisory, an authenticated PostgreSQL user can provide crafted data that triggers an integer overflow caused by a missing overflow check, which can enable arbitrary code execution. ABB’s guidance is to upgrade impacted systems to S+ Engineering 2.4 SP2 RU1 or later, and to use network segmentation and perimeter controls if immediate upgrading is not possible.
- Vendor
- ABB
- Product
- Ability Symphony Plus
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-13
- Original CVE updated
- 2026-04-30
- Advisory published
- 2026-04-13
- Advisory updated
- 2026-04-30
Who should care
Operators, engineers, and defenders responsible for ABB Ability Symphony Plus S+ Engineering deployments in industrial control environments should care, especially where authenticated PostgreSQL access exists or where the S+ client/server network is reachable beyond tightly controlled segments.
Technical summary
The vulnerability is an integer overflow (CWE-190) in ABB Ability Symphony Plus S+ Engineering. The advisory says an attacker with authenticated PostgreSQL user access can supply crafted data and trigger the overflow due to a missing overflow check, potentially leading to arbitrary code execution. The source assigns CVSS v3.1 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). ABB states that exploitation requires access to the site’s S+ client/server network, and that no workaround is available.
Defensive priority
High — verify whether ABB Ability Symphony Plus S+ Engineering is deployed, then upgrade to 2.4 SP2 RU1 or later as soon as possible and restrict S+ client/server network access until remediation is complete.
Recommended defensive actions
- Inventory ABB Ability Symphony Plus S+ Engineering installations and confirm whether any affected versions are in use.
- Upgrade S+ Engineering 2.2 through 2.4 SP2 to S+ Engineering 2.4 SP2 RU1 or later, per ABB guidance.
- If upgrading cannot be done immediately, apply ABB’s mitigation guidance by restricting access to the S+ client/server network and enforcing perimeter firewall and network segmentation controls.
- Follow ABB and CISA industrial control system security recommendations for defense in depth and site-specific risk reduction.
- Treat the issue as requiring prompt action because ABB indicates no workaround is available.
Evidence notes
This debrief is based on the CISA-republished CSAF advisory ICSA-26-120-06 and the referenced ABB PSIRT advisory materials. The source states that CVE-2023-5869 affects ABB Ability Symphony Plus S+ Engineering versions 2.2 through 2.4 SP2, describes the flaw as a missing overflow check leading to integer overflow, and notes that exploitation requires access to the S+ client/server network. Remediation guidance in the source is to upgrade to 2.4 SP2 RU1 or later; the source also states that no workaround is available.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-5869 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-5869
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-5869 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-5869
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-120-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://psirt.abb.com/csaf/2026/7paa017341.json
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.