VYPR

Vendor CVEs

Abb

All CVEs

229 total · sorted by risk
  • CVE-2022-26057MedJun 15, 2022
    risk 0.44cvss 6.7epss 0.00

    Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Mint WorkBench installer file allows a low-privileged user to run a…

  • CVE-2021-22278MedOct 28, 2021
    risk 0.44cvss 6.7epss 0.00

    A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.

  • CVE-2025-7064MedJun 11, 2026
    risk 0.43cvss 6.6epss 0.00

    Authentication bypass by primary weakness vulnerability in ABB Freelance. This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.

  • CVE-2020-8487MedApr 29, 2020
    risk 0.43cvss 6.6epss 0.00

    Insufficient protection of the inter-process communication functions in ABB System 800xA Base (all published versions) enables an attacker authenticated on the local system to inject data, affect node redundancy handling.

  • CVE-2020-8486MedApr 29, 2020
    risk 0.43cvss 6.6epss 0.00

    Insufficient protection of the inter-process communication functions in ABB System 800xA RNRP (all published versions) enables an attacker authenticated on the local system to inject data, affect node redundancy handling.

  • CVE-2026-15952MedSep 28, 2026
    risk 0.42cvss 6.4epss —

    Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.

  • CVE-2025-3756MedApr 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed as affected in this CVE. An attacker with access to IEC 61850 networks could exploit the vulnera bility by using a specially crafted 61850 packet, forcing…

  • CVE-2025-13778MedMar 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

  • CVE-2025-4677MedJan 7, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.

  • CVE-2025-4675MedJan 7, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Check for Unusual or Exceptional Conditions vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.

  • CVE-2025-6074MedJul 3, 2025
    risk 0.42cvss 6.5epss 0.00

    Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to source code and control network, the attacker can bypass the REST interface authentication and gain access to…

  • CVE-2024-1914MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vulnerability could potentially be exploited to perform unauthorized actions by an attacker. This vulnerability arises under specific…

  • CVE-2022-1596MedJun 21, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.

  • CVE-2021-22272MedSep 27, 2021
    risk 0.42cvss 6.5epss 0.01

    The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer the device virtually into her/his my.busch-jaeger.de or mybuildings.abb.com profile. A successful attacker can observe and control…

  • CVE-2020-11420MedApr 27, 2020
    risk 0.42cvss 6.5epss 0.02

    UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and directories outside the web root folder. An…

  • CVE-2019-19093MedApr 2, 2020
    risk 0.42cvss 6.5epss 0.01

    eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.

  • CVE-2019-19001MedApr 2, 2020
    risk 0.42cvss 6.5epss 0.02

    For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as…

  • CVE-2019-19000MedApr 2, 2020
    risk 0.42cvss 6.5epss 0.01

    For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.

  • CVE-2018-17928MedJan 31, 2019
    risk 0.42cvss 6.5epss 0.01

    The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing the user authentication mechanism.

  • CVE-2017-15583MedOct 18, 2017
    risk 0.42cvss 6.5epss 0.01

    The embedded web server on ABB Fox515T 1.0 devices is vulnerable to Local File Inclusion. It accepts a parameter that specifies a file for display or for use as a template. The filename is not validated; an attacker could retrieve any file.

  • CVE-2017-7916MedAug 7, 2017
    risk 0.42cvss 6.5epss 0.01

    A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A…

  • CVE-2016-4524MedJun 10, 2016
    risk 0.42cvss 6.5epss 0.00

    ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.

  • CVE-2023-3324MedJul 24, 2023
    risk 0.41cvss 6.3epss 0.00

    A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the…

  • CVE-2022-26080MedMar 16, 2023
    risk 0.41cvss 6.3epss 0.00

    Use of Insufficiently Random Values vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) –…

  • CVE-2019-19002MedApr 2, 2020
    risk 0.41cvss 6.3epss 0.01

    For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cross Site Scripting.

  • CVE-2025-12143MedNov 28, 2025
    risk 0.40cvss 6.1epss 0.00

    Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

  • CVE-2025-12142MedOct 29, 2025
    risk 0.40cvss 6.1epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

  • CVE-2025-10504MedSep 29, 2025
    risk 0.40cvss 6.1epss 0.00

    Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

  • CVE-2021-22283MedFeb 28, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 series IEC 4.0 FP1, ABB Relion protection relays - 615 series CN 4.0 FP1, ABB Relion protection relays - 615 series IEC 5.0, ABB Relion protection relays - 615…

  • CVE-2022-34837MedAug 24, 2022
    risk 0.40cvss 6.2epss 0.00

    Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.

  • CVE-2022-28702MedJun 2, 2022
    risk 0.40cvss 6.1epss 0.00

    Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.

  • CVE-2021-22276MedSep 23, 2021
    risk 0.40cvss 6.1epss 0.00

    The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.

  • CVE-2019-19107MedApr 22, 2020
    risk 0.40cvss 6.2epss 0.00

    The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidden when displayed).

  • CVE-2019-19105MedApr 22, 2020
    risk 0.40cvss 6.2epss 0.00

    The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credentials of existing user accounts and other configuration's credentials in plaintext.

  • CVE-2019-19096MedApr 2, 2020
    risk 0.40cvss 6.1epss 0.00

    The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, this can potentially compromise the credentials' confidentiality.

  • CVE-2019-19089MedApr 2, 2020
    risk 0.40cvss 6.1epss 0.01

    For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code…

  • CVE-2018-18997MedJan 3, 2019
    risk 0.40cvss 6.1epss 0.01

    Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker using the administrative web interface to insert an HTML/Javascript payload into any of the device properties, which may allow an attacker to display/execute the…

  • CVE-2025-7745MedJul 24, 2025
    risk 0.38cvss 5.8epss 0.00

    Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2.

  • CVE-2024-8036MedOct 25, 2024
    risk 0.38cvss 5.9epss 0.00

    ABB is aware of privately reported vulnerabilities in the product versions referenced in this CVE. An attacker could exploit these vulnerabilities by sending a specially crafted firmware or configuration to the system node, causing the node to stop, become inaccessible, or…

  • CVE-2023-3323MedJul 24, 2023
    risk 0.38cvss 5.9epss 0.00

    A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the…

  • CVE-2023-1258MedMar 31, 2023
    risk 0.38cvss 5.3epss 0.04

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0.

  • CVE-2022-34836MedAug 24, 2022
    risk 0.38cvss 5.9epss 0.01

    Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability could access the Zenon runtime activities…

  • CVE-2019-19097MedApr 2, 2020
    risk 0.38cvss 5.9epss 0.01

    ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might be able to eavesdrop and/or intercept the connection.

  • CVE-2019-7231MedJun 24, 2019
    risk 0.38cvss 5.7epss 0.07

    The ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This overflow is handled, but terminates the process. An authenticated attacker can send a FTP command string of 472 bytes or more to overflow a buffer, causing an…

  • CVE-2018-5477MedFeb 20, 2018
    risk 0.38cvss 5.8epss 0.01

    An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior, netCADOPS Web Application Version 7.2x and prior, netCADOPS Web Application Version 8.0 and prior, and netCADOPS Web Application…

  • CVE-2024-3036MedJun 21, 2024
    risk 0.37cvss 5.7epss 0.00

    Improper Input Validation vulnerability in ABB 800xA Base. An attacker who successfully exploited this vulnerability could cause services to crash by sending specifically crafted messages. This issue affects 800xA Base: from 6.0.0 through 6.1.1-2.

  • CVE-2020-8472MedApr 29, 2020
    risk 0.36cvss 5.5epss 0.00

    Insufficient folder permissions used by system functions in ABB System 800xA products OPCServer for AC800M (versions 6.0 and earlier) and Control Builder M Professional, MMSServer for AC800M, Base Software for SoftControl (version 6.1 and earlier) allow low privileged users to…

  • CVE-2017-14025MedNov 6, 2017
    risk 0.36cvss 5.5epss 0.00

    An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identified, allowing a local attacker to provide a malicious parameter to the script that is not validated by the application, This could enable the…

  • CVE-2023-0580MedApr 6, 2023
    risk 0.35cvss 5.4epss 0.00

    Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My…

  • CVE-2022-3573MedJan 12, 2023
    risk 0.35cvss 5.4epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an…

Page 4 of 5