VYPR

Vendor CVEs

Abb

All CVEs

225 total · sorted by risk
  • CVE-2019-19003MedApr 2, 2020
    risk 0.35cvss 5.3epss 0.01

    For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.

  • CVE-2025-6071MedJul 3, 2025
    risk 0.34cvss 5.3epss 0.00

    Use of Hard-coded Cryptographic Key vulnerability in ABB RMC-100, ABB RMC-100 LITE. An attacker can gain access to salted information to decrypt MQTT information. This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through…

  • CVE-2022-3192MedMar 31, 2023
    risk 0.34cvss 5.3epss 0.01

    Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affects AC500 V2: from 2.0.0 before 2.8.6.

  • CVE-2020-8478MedApr 29, 2020
    risk 0.34cvss 5.3epss 0.00

    Insufficient protection of the inter-process communication functions in ABB System 800xA products OPC Server for AC 800M, MMS Server for AC 800M and Base Software for SoftControl (all published versions) enables an attacker authenticated on the local system to inject data,…

  • CVE-2024-6157MedOct 10, 2024
    risk 0.33cvss 5.1epss 0.00

    An attacker who successfully exploited these vulnerabilities could cause the robot to stop. A vulnerability exists in the PROFINET stack included in the RobotWare versions listed below.  This vulnerability arises under specific condition when specially crafted message is…

  • CVE-2022-1607MedFeb 24, 2023
    risk 0.30cvss 4.6epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842…

  • CVE-2025-13162MedJun 23, 2026
    risk 0.29cvss 4.4epss 0.00

    Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1.

  • CVE-2024-9877MedApr 30, 2025
    risk 0.28cvss 4.3epss 0.00

    : Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

  • CVE-2024-12429MedJan 7, 2025
    risk 0.28cvss 4.3epss 0.00

    An attacker who successfully exploited these vulnerabilities could grant read access to files. A vulnerability exists in the AC500 V3 version mentioned. A successfully authenticated attacker can use this vulnerability to read system wide files and configuration All AC500 V3…

  • CVE-2019-19091MedApr 2, 2020
    risk 0.28cvss 4.3epss 0.01

    For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.

  • CVE-2019-18997MedDec 18, 2019
    risk 0.28cvss 4.3epss 0.02

    The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows access to files outside of the working directory, thus…

  • CVE-2019-18995MedDec 18, 2019
    risk 0.28cvss 4.3epss 0.02

    The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.

  • CVE-2018-17926MedJan 31, 2019
    risk 0.28cvss 4.3epss 0.01

    The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicious language file by bypassing the user authentication mechanism.

  • CVE-2019-18994LowDec 18, 2019
    risk 0.25cvss 3.9epss 0.01

    Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file system might be able to cause application malfunction such…

  • CVE-2019-19092LowApr 2, 2020
    risk 0.23cvss 3.5epss 0.01

    ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.

  • CVE-2019-19090LowApr 2, 2020
    risk 0.23cvss 3.5epss 0.01

    For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.

  • CVE-2016-4527LowJun 10, 2016
    risk 0.21cvss 3.3epss 0.00

    ABB PCM600 before 2.7 improperly stores PCM600 authentication credentials, which allows local users to obtain sensitive information via unspecified vectors.

  • CVE-2016-4516LowJun 10, 2016
    risk 0.21cvss 3.3epss 0.00

    ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.

  • CVE-2023-2876LowJun 13, 2023
    risk 0.20cvss 3.1epss 0.00

    Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0…

  • CVE-2016-4511LowJun 10, 2016
    risk 0.18cvss 2.8epss 0.00

    ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leveraging read access to the ACTConfig configuration file.

  • CVE-2012-0245Mar 9, 2012
    risk 0.01cvss epss 0.08

    Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWare SDK, and WebWare Server, allow remote attackers to…

  • CVE-2008-2474Sep 29, 2008
    risk 0.01cvss epss 0.08

    Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitrary code via a crafted packet using the (1) IEC60870-5-101 or (2) IEC60870-5-104 communication protocol to the X87 web interface.

  • CVE-2014-5430Nov 7, 2014
    risk 0.00cvss epss 0.00

    Untrusted search path vulnerability in ABB RobotStudio 5.6x before 5.61.02 and Test Signal Viewer 1.5 allows local users to gain privileges via a Trojan horse DLL that is accessed as a result of incorrect DLL configuration by an optional installation program.

  • CVE-2013-5021Aug 6, 2013
    risk 0.00cvss epss 0.02

    Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlier, National Instruments LabVIEW 2012 SP1 and earlier, the Data Analysis component in ABB DataManager 1 through 6.3.6, and other…

  • CVE-2012-1801Apr 18, 2012
    risk 0.00cvss epss 0.02

    Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, WebWare SDK, Interlink Module, S4 OPC Server, QuickTeach, RobotStudio S4, and RobotStudio Lite allow remote attackers to execute arbitrary code via crafted input data.

Page 5 of 5