PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-5869 ABB CVE debrief

CVE-2023-5869 affects ABB Ability Symphony Plus S+ Engineering and is rated high severity (CVSS 8.8). According to the advisory, an authenticated PostgreSQL user can provide crafted data that triggers an integer overflow caused by a missing overflow check, which can enable arbitrary code execution. ABB’s guidance is to upgrade impacted systems to S+ Engineering 2.4 SP2 RU1 or later, and to use network segmentation and perimeter controls if immediate upgrading is not possible.

Vendor
ABB
Product
Ability Symphony Plus
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-13
Original CVE updated
2026-04-30
Advisory published
2026-04-13
Advisory updated
2026-04-30

Who should care

Operators, engineers, and defenders responsible for ABB Ability Symphony Plus S+ Engineering deployments in industrial control environments should care, especially where authenticated PostgreSQL access exists or where the S+ client/server network is reachable beyond tightly controlled segments.

Technical summary

The vulnerability is an integer overflow (CWE-190) in ABB Ability Symphony Plus S+ Engineering. The advisory says an attacker with authenticated PostgreSQL user access can supply crafted data and trigger the overflow due to a missing overflow check, potentially leading to arbitrary code execution. The source assigns CVSS v3.1 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). ABB states that exploitation requires access to the site’s S+ client/server network, and that no workaround is available.

Defensive priority

High — verify whether ABB Ability Symphony Plus S+ Engineering is deployed, then upgrade to 2.4 SP2 RU1 or later as soon as possible and restrict S+ client/server network access until remediation is complete.

Recommended defensive actions

  • Inventory ABB Ability Symphony Plus S+ Engineering installations and confirm whether any affected versions are in use.
  • Upgrade S+ Engineering 2.2 through 2.4 SP2 to S+ Engineering 2.4 SP2 RU1 or later, per ABB guidance.
  • If upgrading cannot be done immediately, apply ABB’s mitigation guidance by restricting access to the S+ client/server network and enforcing perimeter firewall and network segmentation controls.
  • Follow ABB and CISA industrial control system security recommendations for defense in depth and site-specific risk reduction.
  • Treat the issue as requiring prompt action because ABB indicates no workaround is available.

Evidence notes

This debrief is based on the CISA-republished CSAF advisory ICSA-26-120-06 and the referenced ABB PSIRT advisory materials. The source states that CVE-2023-5869 affects ABB Ability Symphony Plus S+ Engineering versions 2.2 through 2.4 SP2, describes the flaw as a missing overflow check leading to integer overflow, and notes that exploitation requires access to the S+ client/server network. Remediation guidance in the source is to upgrade to 2.4 SP2 RU1 or later; the source also states that no workaround is available.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-5869 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-5869

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-5869 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-5869

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-120-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://psirt.abb.com/csaf/2026/7paa017341.json

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.