ABB TotalFlow Path Traversal Vulnerability
High risk vulnerability affecting oil and gas companies
https://library.e.abb.com/public/b17396142a3d4d14ae29e351ccc974ec/Cyber%20Security%20Advisory%20CVE-2022-0902%20-%20Path%20Traversal%20Vulnerability%20in%20Totalflow%20TCP%20protocol.pdf
Asea Brown Boveri (ABB), a Swiss industrial automation firm which develops flow computers, a special-purpose electronic instrument used by oil and gas manufacturers to interpret data and calculate oil and gas flow rates and volume are affected by a vulnerability that could allow hackers to cause disruptions and prevent utilities from billing their customers.
Background
A related cyber security incident happened in May 2021, where Colonial Pipeline suffered major disruptions and had to be shut down due to a ransomware attack affecting its billing systems. Any similar attacks can have huge ramifications on operational technologies and poses greater risks to critical supply chains.
Latest Developments
November 8th, 2022: Claroty posted a detailed research on a path-traversal vulnerability in ABB TotalFlow flow computers and controllers and how an attacker could exploit this vulnerability to inject and execute arbitrary code.
Cyber Kill Chain
Reconnaissance
Weaponization
Delivery
Exploitation
FortiGate
Industrial Security Services   22.440
Detects and blocks ABB Path Traversal vulnerability (CVE-2022-0902)
Installation
C2
Action
Endpoint
Incident Response (Security Operations)
To help customers identify and protect vulnerable, FortiAnalyzer, FortiSIEM and FortiSOAR updates are available to raise alerts and escalate to incident response: