Vulnerability index

Browse CVEs

152 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Advabuild HIGH 8.8
CVE-2020-11640

AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the command queue can use it to launch an attack by runn…

Fix: 3.7+
Fix from $1,950 2024-07-23
Advabuild HIGH 7.8
CVE-2020-11639

An attacker could exploit the vulnerability by injecting garbage data or specially crafted data. Depending on the data injected each process might be…

Fix: 3.7+
Fix from $1,950 2024-07-23
Mint Workbench HIGH 7.8
CVE-2024-5402

Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain ele…

Fix: after 5868
Fix from $1,950 2024-07-15
Aspect Ent 12 Firmware CRITICAL 9.8
CVE-2024-6298EPSS 19%

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to e…

Fix: after 3.08.01
Fix from $2,300 2024-07-05
Aspect Ent 12 Firmware HIGH 7.5
CVE-2024-6209EPSS 17%

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to a…

Fix: after 3.08.01
Fix from $1,950 2024-07-05
Aspect Ent 12 Firmware HIGH 8.8
CVE-2024-4007

Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly c…

Fix: 3.07.02+
Fix from $1,950 2024-07-01
800xa Base System MEDIUM 5.7
CVE-2024-3036

Improper Input Validation vulnerability in ABB 800xA Base. An attacker who successfully exploited this vulnerability could cause services to crash b…

Fix: after 6.1.1-2
Fix from $1,600 2024-06-21
2tma310010b0001 Firmware HIGH 8.8
CVE-2024-4008

FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control via access to local KNX Bus-Sys…

Fix: 1.02+
Fix from $1,950 2024-06-05
2tma310010b0001 Firmware HIGH 7.8
CVE-2024-4009

Replay Attack in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to capture/replay KNX telegram to local KN…

Fix: 1.02+
Fix from $1,950 2024-06-05
Robotware MEDIUM 6.5
CVE-2024-1914

An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vulnerabil…

Fix: 6.10.10 / 6.13.07+
Fix from $1,600 2024-05-14
Robotware HIGH 7.6
CVE-2024-1913

An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execute arbitr…

Fix: 6.10.10 / 6.13.07+
Fix from $1,950 2024-05-14
Ac700f Firmware HIGH 7.5
CVE-2023-0426

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the produc…

Fix: 9.2.0+
Fix from $1,950 2023-08-07
Ac700f Firmware HIGH 7.5
CVE-2023-0425

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the produc…

Fix: 9.2.0+
Fix from $1,950 2023-08-07
Ao Opc MEDIUM 6.3
CVE-2023-2685

A vulnerability was found in AO-OPC server versions mentioned above. As the directory information for the service entry is not enclosed in quotation …

Fix: after 3.2.1
Fix from $1,600 2023-07-28
Zenon HIGH 8.8
CVE-2023-3321

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker coul…

Fix: after 11.0.0
Fix from $1,950 2023-07-24
Zenon HIGH 8.1
CVE-2023-3322

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker coul…

Fix: after 11.0.0
Fix from $1,950 2023-07-24
Zenon HIGH 7.5
CVE-2023-3324

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker coul…

Fix: after 11.0.0
Fix from $1,950 2023-07-24
Zenon MEDIUM 5.4
CVE-2023-3323

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker coul…

Fix: after 11.0.0
Fix from $1,600 2023-07-24
Txpert Hub Coretec 4 Firmware HIGH 8.0
CVE-2023-2625

A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any le…

Fix: 3.0.1+
Fix from $1,950 2023-06-28
Rex640 Pcl1 Firmware MEDIUM 6.1
CVE-2023-2876

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (fi…

Fix: 1.0.8 / 1.1.4+
Fix from $1,600 2023-06-13
Aspect Ent 2 Firmware CRITICAL 9.8
CVE-2023-0636

Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S302…

Fix: 3.07.01+
Fix from $2,300 2023-06-05
Aspect Ent 2 Firmware CRITICAL 9.8
CVE-2023-0635

Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203…

Fix: 3.07.01+
Fix from $2,300 2023-06-05
Platform Engineering Tools MEDIUM 5.5
CVE-2022-0010

Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who al…

Fix: after 6.1.0
Fix from $1,600 2023-05-22
Terra Ac Wallbox Ul40 Firmware HIGH 8.8
CVE-2023-0863

Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB…

Fix: 1.2.8 / 1.5.6+
Fix from $1,950 2023-05-17
My Control System CRITICAL 9.8
CVE-2023-0580

Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vuln…

Fix: after 5.13
Fix from $2,300 2023-04-06
Ac500 Cpu Firmware MEDIUM 5.3
CVE-2022-3192

Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affects AC500 V2: from 2.0.0 befo…

Fix: 2.8.6+
Fix from $1,600 2023-03-31
Flow X\/m Firmware MEDIUM 5.3
CVE-2023-1258

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) all…

Fix: after 3.2.6
Fix from $1,600 2023-03-31
Rccmd CRITICAL 9.8
CVE-2022-4126

Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and Passwords.This issue affects R…

Fix: 4.40_230207+
Fix from $2,300 2023-03-27
Symphony Plus S\+ Operations HIGH 8.8
CVE-2023-0228

Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.…

Fix: 2.1 / 3.3+
Fix from $1,950 2023-03-02
Smu615 Firmware MEDIUM 5.5
CVE-2021-22283

Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 series IEC 4.0 FP1, ABB Relion…

Fix: 1.0.2 / 1.0.8+
Fix from $1,600 2023-02-28