Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2020-24683
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the clien…
Symphony \+ Historian
Mitigation only
HIGH 8.8
CVE-2020-24674
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users c…
Symphony \+ Historian
Mitigation only
HIGH 8.8
CVE-2020-24677
Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the u…
Symphony \+ Historian
No fix yet
HIGH 8.8
CVE-2020-24678
An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is a…
Symphony \+ Historian
Mitigation only
HIGH 7.8
CVE-2020-24676
In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authen…
Symphony \+ Historian
Mitigation only
HIGH 7.0
CVE-2020-24680
In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.
Symphony \+ Historian
Mitigation only
CRITICAL 9.8
CVE-2020-10287
The IRC5 family with UAS service enabled comes by default with credentials that can be found on publicly available manuals. ABB considers this a well…
Irb140 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-10288
IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can inpu…
Robotware
Mitigation only
MEDIUM 5.5
CVE-2020-8482
Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user …
Device Library Wizard
after 6.0.3.2
HIGH 7.8
CVE-2020-8484
Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (all published versions) enables an attacker authent…
800xa
Mitigation only
HIGH 7.8
CVE-2020-8485
Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300 (all published versions) enables an attacker aut…
800xa
Mitigation only
HIGH 7.8
CVE-2020-8486
Insufficient protection of the inter-process communication functions in ABB System 800xA RNRP (all published versions) enables an attacker authentica…
800xa Rnrp
Mitigation only
HIGH 7.8
CVE-2020-8487
Insufficient protection of the inter-process communication functions in ABB System 800xA Base (all published versions) enables an attacker authentica…
800xa Base System
Mitigation only
HIGH 7.8
CVE-2020-8488
Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Management (all published versions) enables an attacke…
800xa Batch Management
No fix yet
HIGH 7.8
CVE-2020-8489
Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all published versions) enables an a…
800xa Information Management
Mitigation only
CRITICAL 9.8
CVE-2020-8479
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…
800xa System
Mitigation only
CRITICAL 9.8
CVE-2020-8481
For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder…
800xa System
Mitigation only
HIGH 7.8
CVE-2020-8471
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…
800xa System
Mitigation only
HIGH 7.5
CVE-2020-8475
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…
800xa System
Mitigation only
HIGH 7.5
CVE-2020-8476
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Co…
800xa System
Mitigation only
HIGH 7.8
CVE-2020-8472
Insufficient folder permissions used by system functions in ABB System 800xA products OPCServer for AC800M (versions 6.0 and earlier) and Control Bui…
Control Builder M
after 6.1
HIGH 7.8
CVE-2020-8473
Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low privileged users to read, modif…
800xa Base System
after 6.1
MEDIUM 6.5
CVE-2020-11420
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by man…
Cs141 Firmware
1.90+
CRITICAL 9.1
CVE-2019-19106
Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows an unauthorized user to a…
Tg\/s3.2 Firmware
Mitigation only
HIGH 8.8
CVE-2020-8477
The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker i…
800xa Information Manager
after 6.0.3.2
HIGH 7.8
CVE-2020-8474
Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system function…
800xa Base System
after 6.0.0
MEDIUM 5.5
CVE-2019-19105
The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the ap…
Tg\/s3.2 Firmware
Mitigation only
MEDIUM 5.5
CVE-2019-19107
The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the passwo…
Tg\/s3.2 Firmware
Mitigation only
CRITICAL 9.8
CVE-2019-19104
The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application wit…
Tg\/s3.2 Firmware
Mitigation only
HIGH 8.8
CVE-2019-10995
ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the …
Cp651 Firmware
Mitigation only