Vulnerability index

Browse CVEs

152 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Infinity Dc Power Plant HIGH 8.8
CVE-2022-1607

Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request F…

Fix: 5.0.0+
Fix from $1,950 2023-02-24
Zenon HIGH 8.4
CVE-2022-34838

Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or al…

Fix: after 8.20
Fix from $1,950 2022-08-24
Zenon HIGH 8.2
CVE-2022-34836

Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages an…

Fix: after 8.20
Fix from $1,950 2022-08-24
Zenon MEDIUM 6.1
CVE-2022-34837

Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more …

Fix: after 8.20
Fix from $1,600 2022-08-24
Rmc 100 Firmware CRITICAL 9.8
CVE-2022-0902EPSS 17%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Comma…

Fix: 2105298-024 / 2105457-037+
Fix from $2,300 2022-07-21
Rex640 Pcl1 Firmware MEDIUM 6.5
CVE-2022-1596

Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to …

Fix: 1.1.4 / 1.2.1+
Fix from $1,600 2022-06-21
Automation Builder HIGH 7.8
CVE-2022-31216

Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr…

Fix: 2.7.1+
Fix from $1,950 2022-06-15
Automation Builder HIGH 7.8
CVE-2022-31217

Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr…

Fix: 2.7.1+
Fix from $1,950 2022-06-15
Automation Builder HIGH 7.8
CVE-2022-31218

Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr…

Fix: 2.7.1+
Fix from $1,950 2022-06-15
Automation Builder HIGH 7.8
CVE-2022-31219

Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr…

Fix: 2.7.1+
Fix from $1,950 2022-06-15
Mint Workbench HIGH 7.8
CVE-2022-26057

Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitr…

Fix: after 5866
Fix from $1,950 2022-06-15
E Design HIGH 7.8
CVE-2022-29483

Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating…

Fix: after 1.12.2.0004
Fix from $1,950 2022-06-02
E Design MEDIUM 5.5
CVE-2022-28702

Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating…

Fix: after 1.12.2.0004
Fix from $1,600 2022-06-02
Arg600a1220na Firmware CRITICAL 9.8
CVE-2022-0947

A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial …

Fix: after 3.4.10
Fix from $2,300 2022-05-10
Rtu500 Firmware HIGH 7.5
CVE-2022-28613

A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured…

Fix: 12.0.14.0 / 12.2.12.0+
Fix from $1,950 2022-05-02
800xa HIGH 7.5
CVE-2021-22277

Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, AB…

Fix: 3.0 / 6.0.0-4+
Fix from $1,950 2022-04-01
Pni800 Firmware HIGH 7.5
CVE-2021-22288

Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module un…

Mitigation only
Fix from $1,950 2022-02-04
Opc Server For Ac 800m HIGH 8.8
CVE-2021-22284

Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the nod…

Fix: 6.0.0-4+
Fix from $1,950 2022-02-04
Pni800 Firmware HIGH 7.5
CVE-2021-22285

Improper Handling of Exceptional Conditions, Improper Check for Unusual or Exceptional Conditions vulnerability in the ABB SPIET800 and PNI800 module…

Mitigation only
Fix from $1,950 2022-02-04
Pni800 Firmware HIGH 7.5
CVE-2021-22286

Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module un…

Mitigation only
Fix from $1,950 2022-02-04
Omnicore C30 Firmware CRITICAL 9.8
CVE-2021-22279

A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot contro…

Fix: 7.3.2+
Fix from $2,300 2021-12-13
Update Manager MEDIUM 6.7
CVE-2021-22278

A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which h…

Fix: after 2.10
Fix from $1,600 2021-10-28
Mybuildings CRITICAL 9.4
CVE-2021-22272

The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number in a specific way to transfer …

Fix: 2021-05-03+
Fix from $2,300 2021-09-27
System Access Point 2.0 Firmware MEDIUM 5.5
CVE-2021-22276

The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.

Fix: 2.6.4+
Fix from $1,600 2021-09-23
Base Software CRITICAL 9.8
CVE-2020-24672

A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary code in a computer running the affected product. This…

Fix: after 6.1
Fix from $2,300 2021-09-08
Pm554 Firmware HIGH 7.5
CVE-2020-24686

The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing rem…

Mitigation only
Fix from $1,950 2021-02-26
Ac500 Cpu Firmware HIGH 8.6
CVE-2020-24685

An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability al…

Fix: 2.8.5+
Fix from $1,950 2021-02-09
Symphony \+ Historian CRITICAL 9.8
CVE-2020-24673

In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/…

Mitigation only
Fix from $2,300 2020-12-22
Symphony \+ Historian CRITICAL 9.8
CVE-2020-24675

In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ H…

Mitigation only
Fix from $2,300 2020-12-22
Symphony \+ Historian CRITICAL 9.8
CVE-2020-24679

A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even ex…

Mitigation only
Fix from $2,300 2020-12-22