PatchSiren cyber security CVE debrief
CVE-2023-0286 OpenSSL CVE debrief
CVE-2023-0286 affects ABB M2M Gateway ARM600 firmware 4.1.2 through 5.0.3 and ABB M2M Gateway SW 5.0.1 through 5.0.3. According to the CISA CSAF advisory, the issue can be triggered when CRL checking is enabled and may let an attacker pass arbitrary pointers to a memcmp call, potentially exposing memory contents or causing a denial of service. The supplied advisory classifies the issue as medium severity (CVSS 6.4) and recommends layered mitigations such as minimizing internet exposure, using VPN/DMZ designs, firewall allowlisting, strong credentials, and monitoring.
- Vendor
- OpenSSL
- Product
- PCU400
- CVSS
- MEDIUM 6.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-07
- Original CVE updated
- 2025-04-07
- Advisory published
- 2025-04-07
- Advisory updated
- 2025-04-07
Who should care
Operators and defenders responsible for ABB ARM600 / ABB M2M Gateway deployments, especially environments that use certificate validation with CRL checking or expose remote management and gateway services to broader networks.
Technical summary
The vulnerability is a structure/type mismatch in handling X.400 addresses: they were parsed as ASN1_STRING while the public GENERAL_NAME definition incorrectly declared x400Address as ASN1_TYPE. In affected ABB M2M Gateway ARM600 and SW versions, when CRL checking is enabled, this type confusion can cause a memcmp call to operate on attacker-influenced pointers. The supplied description indicates confidentiality impact (memory contents may be read) and availability impact (denial of service), with no integrity impact in the provided CVSS vector (AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:H).
Defensive priority
Medium, with higher urgency in any deployment that enables CRL checking or relies on affected gateway versions for remote connectivity. Prioritize remediation during the next maintenance window and apply compensating controls immediately if patching cannot be done right away.
Recommended defensive actions
- Inventory ABB M2M Gateway ARM600 and ABB M2M Gateway SW instances and compare them to the affected version ranges in the advisory.
- Reduce or eliminate internet exposure for the ARM600; if remote access is required, limit exposure to the VPN port only.
- Use a DMZ for internet-terminated VPN connections where feasible.
- Apply firewall allowlisting so only required ports, protocols, and hosts are permitted.
- Use non-default, unique, strong administrative credentials and restrict administrator/root use to required tasks.
- Keep supporting engineering/configuration PCs updated, malware-scanned, and dedicated where possible.
- Back up device configurations and validate that backups can be restored.
- Use continuous monitoring and intrusion detection/prevention to detect anomalous behavior around remote access and certificate-handling paths.
Evidence notes
All factual claims are drawn from the supplied CISA CSAF advisory for ICSA-25-105-08 and the ABB references listed in the source corpus. The advisory explicitly names the affected ABB products and version ranges, describes the CRL-checking condition and memcmp pointer issue, and provides mitigation guidance. No KEV entry was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-0286 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-0286
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-0286 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-0286
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-065-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-065-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.