Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2019-18996
Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, pote…
Pb610 Panel Builder 600
after 2.8.0.424
HIGH 7.5
CVE-2019-18997
The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB…
Pb610 Panel Builder 600
after 2.8.0.424
MEDIUM 6.5
CVE-2019-18994
Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load…
Pb610 Panel Builder 600
after 2.8.0.424
MEDIUM 5.3
CVE-2019-18995
The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests…
Pb610 Panel Builder 600
after 2.8.0.424
CRITICAL 9.8
CVE-2019-18250
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, wh…
Plant Connect
Mitigation only
HIGH 8.8
CVE-2019-7225
The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials a…
Cp620 Firmware
after 2.8.0.3674
HIGH 8.8
CVE-2019-7226EPSS 5%
The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged …
Pb610 Panel Builder 600 Firmware
after 2.8.0.367
HIGH 7.3
CVE-2019-7227EPSS 9%
In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP serv…
Pb610 Panel Builder 600 Firmware
after 2.8.0.367
HIGH 8.8
CVE-2019-7228
The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the use…
Pb610 Panel Builder 600 Firmware
after 2.8.0.367
MEDIUM 5.7
CVE-2019-7231EPSS 7%
The ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This overflow is handled, but ter…
Pb610 Panel Builder 600 Firmware
after 2.8.0.367
HIGH 8.3
CVE-2019-7229
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash t…
Board Support Package Un31
2.0.8.424 / 2.8.0.424+
HIGH 8.8
CVE-2019-7230
The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%…
Pb610 Panel Builder 600 Firmware
after 2.8.0.367
HIGH 8.8
CVE-2019-7232EPSS 52%
The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value overflows a buffe…
Pb610 Panel Builder 600 Firmware
after 2.8.0.367
HIGH 7.5
CVE-2019-10953
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers …
Pm554 Tp Eth Firmware
1.10.0.0+
HIGH 7.8
CVE-2018-19008
The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser of the Text Editor wherein the…
Cp400pb Firmware
after 2.0.7.05
MEDIUM 6.5
CVE-2018-17928
The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing the user au…
Cms 770 Firmware
after 1.7.1
CRITICAL 9.8
CVE-2018-18995
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet …
Gate E1 Firmware
Mitigation only
MEDIUM 6.1
CVE-2018-18997
Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker using the administrative web int…
Gate E1 Firmware
Mitigation only
HIGH 7.8
CVE-2018-10616
ABB Panel Builder 800 all versions has an improper input validation vulnerability which may allow an attacker to insert and run arbitrary code on a c…
Panel Builder 800
Mitigation only
CRITICAL 9.8
CVE-2017-7931
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the co…
Ip Gateway Firmware
after 3.39
CRITICAL 9.8
CVE-2017-7933
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized a…
Ip Gateway Firmware
after 3.39
HIGH 8.8
CVE-2017-7906
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow…
Ip Gateway Firmware
after 3.39
CRITICAL 9.8
CVE-2017-9664
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker may acces…
Srea 50 Firmware
after 3.32.8
MEDIUM 5.8
CVE-2018-5477
An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior,…
Netcadops
7.2.10+
HIGH 7.5
CVE-2017-7920
An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versi…
Vsn300 Firmware
after 1.8.15
MEDIUM 6.5
CVE-2017-7916
A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger …
Vsn300 Firmware
after 1.8.15
MEDIUM 6.5
CVE-2016-4524
ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sens…
Pcm600
after 2.6
HIGH 7.2
CVE-2016-2281
Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileges via a Trojan horse DLL in the current working …
Panel Builder 800
Mitigation only
MEDIUM 6.9
CVE-2014-5430
Untrusted search path vulnerability in ABB RobotStudio 5.6x before 5.61.02 and Test Signal Viewer 1.5 allows local users to gain privileges via a Tro…
Robotstudio
Mitigation only
HIGH 7.7
CVE-2012-1801
Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, WebWare SDK, Interlink Module, S4 OPC Server, QuickT…
Interlink Module
Mitigation only