PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-2828 ISC CVE debrief

CVE-2023-2828 is a denial-of-service issue in ABB M2M Gateway ARM600 and ABB M2M Gateway SW. According to the supplied CISA/ABB advisory, querying the resolver for specific RRsets in a certain order can make the configured max-cache-size limit be significantly exceeded, which may exhaust host memory and disrupt the named service. ABB also states that ARM600 is not dependent on DNS by default, and recommends blocking TCP/UDP port 53 when name service is not needed.

Vendor
ISC
Product
ABB M2M Gateway
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-07
Original CVE updated
2025-04-07
Advisory published
2025-04-07
Advisory updated
2025-04-07

Who should care

Operators, administrators, and OT security teams responsible for ABB M2M Gateway ARM600 and ABB M2M Gateway SW deployments, especially where the named service or DNS is enabled or reachable.

Technical summary

The advisory describes a resolver-cache memory exhaustion condition: specific RRset query ordering can bypass the intended max-cache-size behavior and cause the host running named to consume all available memory, resulting in denial of service. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H.

Defensive priority

Medium. The impact is availability-only, but the issue is network-exploitable and can lead to full memory exhaustion on the affected host, so exposed deployments should be reviewed promptly.

Recommended defensive actions

  • Verify whether your environment uses ABB M2M Gateway ARM600 firmware versions 4.1.2 through 5.0.3 or ABB M2M Gateway SW versions 5.0.1 through 5.0.3.
  • If name service is not required, block TCP/UDP port 53 with a firewall, as ABB recommends.
  • Review ABB's general security recommendations for the ARM600 system and reduce unnecessary exposure of the named service.
  • Monitor affected hosts for abnormal memory growth or service instability and prepare operational recovery procedures.

Evidence notes

The supplied source corpus states that the vulnerability can cause the configured max-cache-size limit to be significantly exceeded by querying the resolver for specific RRsets in a certain order, leading to denial of service by exhausting memory on the host running named. It also states that ARM600 is not dependent on DNS by default and recommends blocking TCP/UDP port 53 if name service is unused. The advisory provided in the corpus is CISA CSAF ICSA-25-105-08, published 2025-04-07.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-2828 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-2828

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-2828 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-2828

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-08.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://library.e.abb.com/public/0498e4c0babd46aa9243aedd6f99c375/ARM600_user_758861_ENk.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://library.e.abb.com/public/ffab1a14a42646c6adee38fc3de61dad/Arctic_csdepl_758860_ENf.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-08

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.