Vulnerability index

Browse CVEs

152 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Symphony \+ Historian CRITICAL 9.8
CVE-2020-24683

The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the clien…

Mitigation only
Fix from $2,300 2020-12-22
Symphony \+ Historian HIGH 8.8
CVE-2020-24674

In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users c…

Mitigation only
Fix from $1,950 2020-12-22
Symphony \+ Historian HIGH 8.8
CVE-2020-24677

Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the u…

No fix yet
Fix from $1,950 2020-12-22
Symphony \+ Historian HIGH 8.8
CVE-2020-24678

An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is a…

Mitigation only
Fix from $1,950 2020-12-22
Symphony \+ Historian HIGH 7.8
CVE-2020-24676

In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authen…

Mitigation only
Fix from $1,950 2020-12-22
Symphony \+ Historian HIGH 7.0
CVE-2020-24680

In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.

Mitigation only
Fix from $1,950 2020-12-22
Irb140 Firmware CRITICAL 9.8
CVE-2020-10287

The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well…

Mitigation only
Fix from $2,300 2020-07-15
Robotware CRITICAL 9.8
CVE-2020-10288

IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can inpu…

Mitigation only
Fix from $2,300 2020-07-15
Device Library Wizard MEDIUM 5.5
CVE-2020-8482

Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user …

Fix: after 6.0.3.2
Fix from $1,600 2020-05-29
800xa HIGH 7.8
CVE-2020-8484

Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (all published versions) enables an attacker authent…

Mitigation only
Fix from $1,950 2020-04-29
800xa HIGH 7.8
CVE-2020-8485

Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300 (all published versions) enables an attacker aut…

Mitigation only
Fix from $1,950 2020-04-29
800xa Rnrp HIGH 7.8
CVE-2020-8486

Insufficient protection of the inter-process communication functions in ABB System 800xA RNRP (all published versions) enables an attacker authentica…

Mitigation only
Fix from $1,950 2020-04-29
800xa Base System HIGH 7.8
CVE-2020-8487

Insufficient protection of the inter-process communication functions in ABB System 800xA Base (all published versions) enables an attacker authentica…

Mitigation only
Fix from $1,950 2020-04-29
800xa Batch Management HIGH 7.8
CVE-2020-8488

Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Management (all published versions) enables an attacke…

No fix yet
Fix from $1,950 2020-04-29
800xa Information Management HIGH 7.8
CVE-2020-8489

Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all published versions) enables an a…

Mitigation only
Fix from $1,950 2020-04-29
800xa System CRITICAL 9.8
CVE-2020-8479

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…

Mitigation only
Fix from $2,300 2020-04-29
800xa System CRITICAL 9.8
CVE-2020-8481

For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder…

Mitigation only
Fix from $2,300 2020-04-29
800xa System HIGH 7.8
CVE-2020-8471

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…

Mitigation only
Fix from $1,950 2020-04-29
800xa System HIGH 7.5
CVE-2020-8475

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…

Mitigation only
Fix from $1,950 2020-04-29
800xa System HIGH 7.5
CVE-2020-8476

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…

Mitigation only
Fix from $1,950 2020-04-29
Control Builder M HIGH 7.8
CVE-2020-8472

Insufficient folder permissions used by system functions in ABB System 800xA products OPCServer for AC800M (versions 6.0 and earlier) and Control Bui…

Fix: after 6.1
Fix from $1,950 2020-04-29
800xa Base System HIGH 7.8
CVE-2020-8473

Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low privileged users to read, modif…

Fix: after 6.1
Fix from $1,950 2020-04-29
Cs141 Firmware MEDIUM 6.5
CVE-2020-11420

UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by man…

Fix: 1.90+
Fix from $1,600 2020-04-27
Tg\/s3.2 Firmware CRITICAL 9.1
CVE-2019-19106

Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows an unauthorized user to a…

Mitigation only
Fix from $2,300 2020-04-22
800xa Information Manager HIGH 8.8
CVE-2020-8477

The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker i…

Fix: after 6.0.3.2
Fix from $1,950 2020-04-22
800xa Base System HIGH 7.8
CVE-2020-8474

Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system function…

Fix: after 6.0.0
Fix from $1,950 2020-04-22
Tg\/s3.2 Firmware MEDIUM 5.5
CVE-2019-19105

The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the ap…

Mitigation only
Fix from $1,600 2020-04-22
Tg\/s3.2 Firmware MEDIUM 5.5
CVE-2019-19107

The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the passwo…

Mitigation only
Fix from $1,600 2020-04-22
Tg\/s3.2 Firmware CRITICAL 9.8
CVE-2019-19104

The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application wit…

Mitigation only
Fix from $2,300 2020-04-22
Cp651 Firmware HIGH 8.8
CVE-2019-10995

ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the …

Mitigation only
Fix from $1,950 2020-01-14