ABB M2M Gateway Abitrary Code Execution in embedded Git (CVE-2023-25652)

high Tenable OT Security Plugin ID 503250

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwritten with partially controlled contents (corresponding to the rejected hunk(s) from the given patch). A fix is available in versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1. As a workaround, avoid using `git apply` with `--reject` when applying patches from an untrusted source. Use `git apply --stat` to inspect a patch before applying; avoid applying one that create a conflict where a link corresponding to the `*.rej` file exists.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-08

http://www.nessus.org/u?310ae51a

http://www.openwall.com/lists/oss-security/2023/04/25/2

http://www.nessus.org/u?e05ec26f

http://www.nessus.org/u?da573138

https://github.com/git/git/security/advisories/GHSA-2hvf-7c8p-28fx

https://lists.debian.org/debian-lts-announce/2024/06/msg00018.html

http://www.nessus.org/u?a8612e69

http://www.nessus.org/u?85f6a28a

http://www.nessus.org/u?5febbcc9

http://www.nessus.org/u?f5f44280

https://security.gentoo.org/glsa/202312-15

Plugin Details

Severity: High

ID: 503250

Version: 1.1

Type: remote

Family: Tenable.ot

Published: 5/27/2025

Updated: 5/27/2025

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Vulnerability Information

CPE: cpe:/o:abb:sw_firmware, cpe:/o:abb:arm600_firmware

Required KB Items: Tenable.ot/ABB

Exploit Ease: No known exploits are available

Patch Publication Date: 4/25/2023

Vulnerability Publication Date: 4/25/2023

Reference Information

CVE: CVE-2023-25652

CWE: 22

ICSA: 25-105-08