VYPR

Vendor CVEs

Abb

All CVEs

225 total · sorted by risk
  • CVE-2023-0863HigMay 17, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC…

  • CVE-2023-0228HigMar 2, 2023
    risk 0.57cvss 8.8epss 0.00

    Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.

  • CVE-2022-3388HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.00

    An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.

  • CVE-2020-24678HigDec 22, 2020
    risk 0.57cvss 8.8epss 0.01

    An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges.

  • CVE-2020-24677HigDec 22, 2020
    risk 0.57cvss 8.8epss 0.01

    Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data.

  • CVE-2020-24674HigDec 22, 2020
    risk 0.57cvss 8.8epss 0.03

    In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.

  • CVE-2020-8477HigApr 22, 2020
    risk 0.57cvss 8.8epss 0.02

    The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.

  • CVE-2019-10995HigJan 14, 2020
    risk 0.57cvss 8.8epss 0.01

    ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the HMI interface.

  • CVE-2019-7225HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.03

    The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. These…

  • CVE-2019-7228HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.04

    The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.

  • CVE-2019-7230HigJun 24, 2019
    risk 0.57cvss 8.8epss 0.04

    The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.

  • CVE-2017-7906HigJun 6, 2018
    risk 0.57cvss 8.8epss 0.01

    In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.

  • CVE-2017-16731HigDec 20, 2017
    risk 0.57cvss 8.8epss 0.01

    An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to LDAP/AD using the LDAP protocol. An attacker could exploit…

  • CVE-2023-0426HigAug 7, 2023
    risk 0.56cvss 8.6epss 0.00

    ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product…

  • CVE-2023-0425HigAug 7, 2023
    risk 0.56cvss 8.6epss 0.00

    ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product…

  • CVE-2020-24685HigFeb 9, 2021
    risk 0.56cvss 8.6epss 0.02

    An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR LED flashing red), physical access to the PLC is required in order to restart…

  • CVE-2021-22284HigFeb 4, 2022
    risk 0.55cvss 8.4epss 0.01

    Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the node running the AC800M OPC Server.

  • CVE-2025-13779HigMar 13, 2026
    risk 0.54cvss 8.3epss 0.00

    Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

  • CVE-2025-13777HigMar 13, 2026
    risk 0.54cvss 8.3epss 0.00

    Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

  • CVE-2024-51544HigDec 5, 2024
    risk 0.54cvss 8.2epss 0.14

    Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2022-0902HigJul 21, 2022
    risk 0.54cvss 8.1epss 0.17

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5…

  • CVE-2019-7229HigJun 24, 2019
    risk 0.54cvss 8.3epss 0.01

    The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements…

  • CVE-2025-14510HigJan 16, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Ability OPTIMAX: 6.1, 6.2, from 6.3.0 before 6.3.1-251120, from 6.4.0 before 6.4.1-251120.

  • CVE-2024-51543HigDec 5, 2024
    risk 0.53cvss 8.2epss 0.00

    Information Disclosure vulnerabilities allow access to application configuration information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2024-51542HigDec 5, 2024
    risk 0.53cvss 8.2epss 0.00

    Configuration Download vulnerabilities allow access to dependency configuration information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2024-51541HigDec 5, 2024
    risk 0.53cvss 8.2epss 0.00

    Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2024-48847HigDec 5, 2024
    risk 0.53cvss 8.2epss 0.00

    MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.  Affected products: ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01; MATRIX Series v3.08.01

  • CVE-2024-48844HigDec 5, 2024
    risk 0.53cvss 7.7epss 0.01

    Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2022-34838HigAug 24, 2022
    risk 0.53cvss 8.1epss 0.00

    Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the…

  • CVE-2025-14773HigJun 3, 2026
    risk 0.52cvss 8.0epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

  • CVE-2021-22291HigOct 7, 2025
    risk 0.52cvss 8.0epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.

  • CVE-2024-9639HigMay 22, 2025
    risk 0.52cvss 8.0epss 0.01

    Remote Code Execution vulnerabilities are present in ASPECT if session administra-tor credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.

  • CVE-2024-51546HigDec 5, 2024
    risk 0.52cvss 7.5epss 0.01

    Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2025-3394HigApr 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

  • CVE-2020-11639HigJul 23, 2024
    risk 0.51cvss 7.8epss 0.00

    An attacker could exploit the vulnerability by injecting garbage data or specially crafted data. Depending on the data injected each process might be affected differently. The process could crash or cause communication issues on the affected node, effectively causing a…

  • CVE-2024-5402HigJul 15, 2024
    risk 0.51cvss 7.8epss 0.00

    Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an executable file in the path of the affected service. This issue affects Mint Workbench I…

  • CVE-2023-0635HigJun 5, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021,…

  • CVE-2022-0010HigMay 22, 2023
    risk 0.51cvss 7.8epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information,…

  • CVE-2022-31218HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a…

  • CVE-2022-31217HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a…

  • CVE-2022-31216HigJun 15, 2022
    risk 0.51cvss 7.8epss 0.00

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a…

  • CVE-2022-29483HigJun 2, 2022
    risk 0.51cvss 7.8epss 0.00

    Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.

  • CVE-2020-24676HigDec 22, 2020
    risk 0.51cvss 7.8epss 0.00

    In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.

  • CVE-2020-8482HigMay 29, 2020
    risk 0.51cvss 7.8epss 0.00

    Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data

  • CVE-2020-8489HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all published versions) enables an attacker authenticated on the local system to inject data, affecting the runtime values to be stored in the archive, or making…

  • CVE-2020-8488HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Management (all published versions) enables an attacker authenticated on the local system to inject data, affecting User Interface update during batch execution and/or compare/printing…

  • CVE-2020-8485HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300 (all published versions) enables an attacker authenticated on the local system to inject data, allowing reads and writes to the controllers or cause windows processes to crash.

  • CVE-2020-8484HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (all published versions) enables an attacker authenticated on the local system to inject data, allowing reads and writes to the controllers or cause windows processes to crash.

  • CVE-2020-8471HigApr 29, 2020
    risk 0.51cvss 7.8epss 0.00

    For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+…

  • CVE-2020-8474HigApr 22, 2020
    risk 0.51cvss 7.8epss 0.00

    Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction.

Page 2 of 5