VYPR

Vendor CVEs

Abb

All CVEs

225 total · sorted by risk
  • CVE-2018-19008HigFeb 13, 2019
    risk 0.51cvss 7.8epss 0.02

    The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser of the Text Editor wherein the application doesn't properly prevent the insertion of specially crafted files which could allow arbitrary code execution.

  • CVE-2018-10616HigJul 18, 2018
    risk 0.51cvss 7.8epss 0.01

    ABB Panel Builder 800 all versions has an improper input validation vulnerability which may allow an attacker to insert and run arbitrary code on a computer where the affected product is used.

  • CVE-2018-1168HigFeb 21, 2018
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific…

  • CVE-2024-48843HigDec 5, 2024
    risk 0.50cvss 7.7epss 0.00

    Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2025-8754HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.00

    Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14.

  • CVE-2025-6073HigJul 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and user/password broker authentication is enabled, and CVE-2025-6074 is exploited, the attacker can…

  • CVE-2025-6072HigJul 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and CVE-2025-6074 is exploited, the attacker can use the JSON configuration to overflow the date of…

  • CVE-2024-48846HigDec 5, 2024
    risk 0.49cvss 7.1epss 0.01

    Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2024-11316HigDec 5, 2024
    risk 0.49cvss 7.5epss 0.01

    Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

  • CVE-2024-1913HigMay 14, 2024
    risk 0.49cvss 7.6epss 0.01

    An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execute arbitrary code.  The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability…

  • CVE-2024-0335HigApr 3, 2024
    risk 0.49cvss 7.5epss 0.01

    ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst) This issue affects Symphony Plus S+ Operations: from 3..0;0 through…

  • CVE-2022-28613HigMay 2, 2022
    risk 0.49cvss 7.5epss 0.01

    A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500…

  • CVE-2021-22277HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service.

  • CVE-2021-22288HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive.

  • CVE-2021-22286HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive.

  • CVE-2021-22285HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.01

    Improper Handling of Exceptional Conditions, Improper Check for Unusual or Exceptional Conditions vulnerability in the ABB SPIET800 and PNI800 module that allows an attacker to cause the denial of service or make the module unresponsive.

  • CVE-2020-24686HigFeb 26, 2021
    risk 0.49cvss 7.5epss 0.01

    The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC while this vulnerability is exploited, the PLC will show…

  • CVE-2020-24679HigDec 22, 2020
    risk 0.49cvss 7.5epss 0.02

    A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.

  • CVE-2019-19094HigApr 2, 2020
    risk 0.49cvss 7.6epss 0.01

    Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.

  • CVE-2019-10953HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.03

    ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network packets.

  • CVE-2018-20720HigJan 16, 2019
    risk 0.49cvss 7.5epss 0.02

    ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot) via a reboot command in an SPA message.

  • CVE-2017-7920HigAug 7, 2017
    risk 0.49cvss 7.5epss 0.03

    An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access…

  • CVE-2016-4526HigSep 19, 2016
    risk 0.49cvss 7.5epss 0.00

    ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.

  • CVE-2025-14774HigJun 3, 2026
    risk 0.48cvss 7.4epss 0.00

    Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

  • CVE-2025-9970HigOct 8, 2025
    risk 0.48cvss 7.4epss 0.00

    Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.4.9.21.

  • CVE-2019-7227HigJun 27, 2019
    risk 0.48cvss 7.3epss 0.09

    In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP server functionality to download and upload files. An unauthenticated attacker can take advantage of the hardcoded or default…

  • CVE-2025-10207HigSep 18, 2025
    risk 0.47cvss 7.2epss 0.00

    Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5.

  • CVE-2024-48851HigSep 18, 2025
    risk 0.47cvss 7.2epss 0.01

    Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an improper input validation. This issue affects FLXEON: through 9.3.5.

  • CVE-2024-9876HigApr 30, 2025
    risk 0.47cvss 7.3epss 0.00

    : Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

  • CVE-2024-10334HigFeb 10, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability exists in the VideONet product included in the listed System 800xA versions, where VideONet is used.  An attacker who successfully exploited the vulnerability could, in the worst case scenario, stop or manipulate the video feed. This issue affects System 800xA:…

  • CVE-2023-2685HigJul 28, 2023
    risk 0.47cvss 7.2epss 0.00

    A vulnerability was found in AO-OPC server versions mentioned above. As the directory information for the service entry is not enclosed in quotation marks, potential attackers could possibly call up another application than the AO-OPC server by starting the service. The service…

  • CVE-2023-0636HigJun 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021,…

  • CVE-2022-31219HigJun 15, 2022
    risk 0.47cvss 7.3epss 0.00

    Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a…

  • CVE-2020-8473HigApr 29, 2020
    risk 0.47cvss 7.3epss 0.00

    Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low privileged users to read, modify, add and delete system and application files. An authenticated attacker who successfully exploit the vulnerabilities could…

  • CVE-2016-2281HigMar 18, 2016
    risk 0.47cvss 7.2epss 0.00

    Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

  • CVE-2025-3465HigOct 20, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB CoreSense™ M10.This issue affects CoreSense™ HM: through 2.3.1; CoreSense™ M10: through 1.4.1.12.

  • CVE-2024-48842HigSep 17, 2025
    risk 0.46cvss 7.0epss 0.00

    Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions

  • CVE-2025-3395HigApr 30, 2025
    risk 0.46cvss 7.1epss 0.00

    Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

  • CVE-2024-12430HigJan 7, 2025
    risk 0.46cvss 7.0epss 0.00

    An attacker who successfully exploited these vulnerabilities could cause enable command execution. A vulnerability exists in the AC500 V3 version mentioned. After successfully exploiting CVE-2024-12429 (directory traversal), a successfully authenticated attacker can inject…

  • CVE-2023-3322HigJul 24, 2023
    risk 0.46cvss 7.0epss 0.00

    A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the…

  • CVE-2023-3321HigJul 24, 2023
    risk 0.46cvss 7.0epss 0.00

    A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the…

  • CVE-2023-0864HigMay 17, 2023
    risk 0.46cvss 7.1epss 0.00

    Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE)…

  • CVE-2020-24680HigDec 22, 2020
    risk 0.46cvss 7.0epss 0.00

    In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.

  • CVE-2019-18998HigFeb 17, 2020
    risk 0.46cvss 7.1epss 0.01

    Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.

  • CVE-2019-18996HigDec 18, 2019
    risk 0.46cvss 7.1epss 0.00

    Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.

  • CVE-2025-5517MedOct 20, 2025
    risk 0.44cvss 6.8epss 0.00

    Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (MID/ CE) -Terra AC MID, ABB Terra AC wallbox (MID/ CE) -Terra AC Juno CE, ABB Terra AC wallbox (MID/ CE) -Terra AC PTB, ABB Terra AC wallbox (JP).This…

  • CVE-2025-7705MedJul 22, 2025
    risk 0.44cvss 6.8epss 0.00

    : Active Debug Code vulnerability in ABB Switch Actuator 4 DU-83330, ABB Switch actuator, door/light 4 DU -83330-500.This issue affects Switch Actuator 4 DU-83330: All Versions; Switch actuator, door/light 4 DU -83330-500: All Versions.

  • CVE-2025-4407MedJun 30, 2025
    risk 0.44cvss 6.7epss 0.00

    Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1.

  • CVE-2022-26057MedJun 15, 2022
    risk 0.44cvss 6.7epss 0.00

    Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Mint WorkBench installer file allows a low-privileged user to run a…

  • CVE-2021-22278MedOct 28, 2021
    risk 0.44cvss 6.7epss 0.00

    A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.