Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fox615 Firmware HIGH 7.1
CVE-2021-40333

Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Net…

Mitigation only
Fix from $1,950 2021-12-02
Rtu500 Firmware HIGH 7.5
CVE-2021-35533

Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-5-104 function of Hitachi Ene…

Mitigation only
Fix from $1,950 2021-11-26
Gms600 Firmware HIGH 7.2
CVE-2021-35534

Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC…

Mitigation only
Fix from $1,950 2021-11-18
Relion 670 Firmware HIGH 8.1
CVE-2021-35535

Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front …

Fix: after 2.2.3.3
Fix from $1,950 2021-11-18
Counterparty Settlements And Billing HIGH 7.1
CVE-2021-35528

Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlemen…

Fix: after 5.7.3
Fix from $1,950 2021-11-17
Counterparty Settlement And Billing HIGH 7.2
CVE-2021-35529

Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Bil…

Fix: 5.7.3+
Fix from $1,950 2021-08-20
Esoms HIGH 7.5
CVE-2021-35527

Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user cre…

Fix: 6.3.1+
Fix from $1,950 2021-07-14
Relion 670 Firmware HIGH 7.5
CVE-2021-27196

Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, RE…

Fix: 1.2.3.20 / 1.3.0.7+
Fix from $1,950 2021-06-14
Esoms HIGH 7.5
CVE-2021-26845

Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access …

Fix: 6.0.4.2.2 / 6.1.4+
Fix from $1,950 2021-06-14
Microscada Pro Sys600 CRITICAL 9.8
CVE-2019-5620EPSS 70%

ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.

No fix yet
Fix from $2,300 2020-04-29
Esoms HIGH 7.6
CVE-2019-19094

Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.

Fix: after 6.0.3
Fix from $1,950 2020-04-02
Esoms HIGH 7.5
CVE-2019-19097

ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might b…

Fix: after 6.0.3
Fix from $1,950 2020-04-02
Esoms MEDIUM 6.1
CVE-2019-19096

The Redis data structure component used in ABB eSOMS versions 6.0 to 6.0.2 stores credentials in clear text. If an attacker has file system access, t…

Fix: after 6.0.2
Fix from $1,600 2020-04-02
Esoms MEDIUM 5.4
CVE-2019-19095

Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by…

Fix: after 6.0.2
Fix from $1,600 2020-04-02
Esoms MEDIUM 6.5
CVE-2019-19093

eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user password…

Fix: after 6.0.3
Fix from $1,600 2020-04-02
Esoms MEDIUM 6.1
CVE-2019-19003

For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enabl…

Fix: after 6.0.2
Fix from $1,600 2020-04-02
Esoms MEDIUM 6.1
CVE-2019-19089

For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be i…

Fix: after 6.0.3
Fix from $1,600 2020-04-02
Esoms MEDIUM 5.4
CVE-2019-19002

For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not…

Fix: after 6.0.2
Fix from $1,600 2020-04-02
Esoms MEDIUM 6.5
CVE-2019-19000

For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can p…

Fix: after 6.0.3
Fix from $1,600 2020-04-02
Esoms MEDIUM 6.5
CVE-2019-19001

For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks…

Fix: after 6.0.2
Fix from $1,600 2020-04-02
Asset Suite HIGH 7.1
CVE-2019-18998

Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables…

Fix: 9.4.2.6 / 9.5.3.2+
Fix from $1,950 2020-02-17
Relion 670 Firmware CRITICAL 10.0
CVE-2019-18253

An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.…

Fix: 1.2.3.17 / 1p1r26+
Fix from $2,300 2019-11-27
Relion 650 Firmware HIGH 7.5
CVE-2019-18247

An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.…

Fix: after 2.1.0.1
Fix from $1,950 2019-11-27
Relion 630 Firmware HIGH 7.5
CVE-2018-20720

ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot)…

Fix: 1.1.0.c0 / 1.2.0.b3+
Fix from $1,950 2019-01-16
Esoms CRITICAL 9.8
CVE-2018-14805

ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values withi…

Mitigation only
Fix from $2,300 2018-08-29
Sys600 Firmware HIGH 7.8
CVE-2018-1168

This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must fi…

Mitigation only
Fix from $1,950 2018-02-21
Ellipse HIGH 8.8
CVE-2017-16731

An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellips…

Fix: after 8.9.0
Fix from $1,950 2017-12-20
Fox515t Firmware MEDIUM 5.5
CVE-2017-14025

An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identified, allowin…

Mitigation only
Fix from $1,600 2017-11-06
Fox515t Firmware MEDIUM 6.5
CVE-2017-15583

The embedded web server on ABB Fox515T 1.0 devices is vulnerable to Local File Inclusion. It accepts a parameter that specifies a file for display or…

Mitigation only
Fix from $1,600 2017-10-18