logo

Oil and Gas Weak Spot: ABB TotalFlow Computers

ID: e092f358-2a2f-5cf2-9411-83a7d160853d

STIX ID: report--e092f358-2a2f-5cf2-9411-83a7d160853d

Feed Name: Claroty Team82

Threat Score
75/100

Date Published: 2023-07-25

Date Updated: 2026-04-17

Author: Vera Mens

...
...

Team82 discovered and disclosed a high-severity path-traversal vulnerability (CVE-2022-0902, CWE-22, CVSS 8.1) in ABB TotalFlow flow computers and controllers that allows attackers to read/write arbitrary files and achieve remote code execution as root. The report documents reverse engineering of the TotalFlow protocol, an authentication bypass via CRC-16-protected 4-digit passcodes, a proof-of-concept exploit (reading /etc/shadow, enabling SSH), affected product models, and mitigation steps including a firmware update and network segmentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.