PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-47614 Telit Cinterion CVE debrief

ABB Arctic Wireless Gateways are affected by a low-severity information disclosure issue. Per the CISA advisory published on 2025-04-07, a local attacker with low privileges could disclose hidden virtual paths and file names on the wireless modem module. The advisory covers ARG600, ARC600, and ARR600 devices using the Telit PLS62-W wireless modem module and assigns CVSS 3.2 (LOW).

Vendor
Telit Cinterion
Product
Arctic Wireless Gateways
CVSS
LOW 3.2
CISA KEV
Not listed in stored evidence
Original CVE published
2025-04-07
Original CVE updated
2025-04-07
Advisory published
2025-04-07
Advisory updated
2025-04-07

Who should care

OT/ICS teams operating ABB Arctic Wireless Gateways, especially ARG600, ARC600, and ARR600 systems with Telit PLS62-W wireless modem modules. Administrators should pay particular attention if devices have local access paths, exposed SSH administration, active SMS/cellular services, or weak physical access controls.

Technical summary

CISA's CSAF advisory ICSA-25-100-09 identifies CVE-2023-47614 in ABB Arctic Wireless Gateway ARG600, ARC600, and ARR600 products that use the Telit PLS62-W wireless modem module. The vulnerability is described as an exposure of sensitive information that could allow a local, low-privileged attacker to learn hidden virtual paths and file names on the modem module. The advisory lists CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N, with a score of 3.2.

Defensive priority

Low, but worth addressing on any deployed gateway where local access, physical access, SSH administration, or cellular services are not tightly controlled.

Recommended defensive actions

  • Follow ABB and CISA guidance for the affected Arctic Wireless Gateway models and confirm whether ARG600, ARC600, or ARR600 devices are in use.
  • Use a private cellular access point where feasible to reduce exposure.
  • Ask the mobile network operator to disable binary SMS for the subscription; if SMS is not needed, disable SMS services entirely.
  • Do not expose SSH to public networks; restrict remote administration to a secure VPN such as OpenVPN.
  • Restrict physical access to the product and its connected modem module.
  • Review the referenced ABB product documentation and general ICS security recommendations linked in the advisory.

Evidence notes

All factual statements are drawn from the supplied CISA CSAF advisory record and its official references. The advisory was initially published and modified on 2025-04-07 (ICSA-25-100-09 / CVE-2023-47614). No exploit steps, weaponization details, or unsupported claims are included.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-47614 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-47614

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-47614 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-47614

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-100-09.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-09

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.