VYPR

Asset Suite

by Hitachienergy

CVEs (4)

  • CVE-2025-2500HigMay 30, 2025
    risk 0.48cvss 7.4epss 0.00

    A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an attacker could gain unauthorized access to the product and the time window of a possible password attack could be expanded.

  • CVE-2019-18998HigFeb 17, 2020
    risk 0.46cvss 7.1epss 0.01

    Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.

  • CVE-2023-4816MedSep 11, 2023
    risk 0.45cvss 6.9epss 0.01

    A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. This vulnerability can be exploited by an authenticated user per-forming an Equipment Tag Out holder action (Accept, Release, and Clear)…

  • CVE-2025-10217MedSep 30, 2025
    risk 0.39cvss epss 0.00

    A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in logfile for potentially carrying out further malicious attacks. Performance logging is typically enabled for troubleshooting…