AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›ABB
AB
Platform

ABB

Global technology leader in electrification and automation. Products include AC500 PLCs, ACS880 drives, IRC5 robot controllers, and System 800xA DCS.

https://new.abb.com/plc →
236
Total CVEs
10
Resources
39
CRIT
98
HIGH
88
MED
8
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
98 / 236
CVE-2012-0245HIGH

Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWare SDK, and WebWare Server, allow remote attackers to execute arbitrary code via a crafted (1) 0xA or (2) 0xE Netscan packet.

Mar 9, 2012
10.0
CVE-2008-2474HIGH

Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitrary code via a crafted packet using the (1) IEC60870-5-101 or (2) IEC60870-5-104 communication protocol to the X87 web interface.

Sep 29, 2008
10.0
CVE-2013-5021HIGH

Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlier, National Instruments LabVIEW 2012 SP1 and earlier, the Data Analysis component in ABB DataManager 1 through 6.3.6, and other products allow remote attackers to create and execute arbitrary files via a full pathname in an argument to the ExportStyle method in the (1) CWNumEdit, (2) CWGraph, (3) CWBoolean, (4) CWSlide, or (5) CWKnob ActiveX control, in conjunction with file content in the (a) Caption or (b) FormatString property value.

Aug 6, 2013
9.3
CVE-2026-32059HIGH

OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fails to properly validate GNU long-option abbreviations, allowing attackers to bypass denied-flag checks via abbreviated options. Remote attackers can execute sort commands with abbreviated long options to skip approval requirements in allowlist mode.

Mar 11, 2026
8.8
CVE-2025-4676HIGH

Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.

Jan 7, 2026
8.8
CVE-2025-10205HIGH

Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and newer versions

Sep 17, 2025
8.8
CVE-2024-45044HIGH

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user executes a command in bconsole using an abbreviation (i.e. "w" for "whoami") the ACL check did not apply to the full form (i.e. "whoami") but to the abbreviated form (i.e. "w"). If the command ACL is configured with negative ACL that should forbid using the "whoami" command, you could still use "w" or "who" as a command successfully. Fixes for the problem are shipped in Bareos versions 23.0.4, 22.1.6 and 21.1.11. If only positive command ACLs are used without any negation, the problem does not occur.

Sep 10, 2024
8.8
CVE-2020-11640HIGH

AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the command queue can use it to launch an attack by running any executable on the AdvaBuild node. The executables that can be run are not limited to AdvaBuild specific executables.  Improper Privilege Management vulnerability in ABB Advant MOD 300 AdvaBuild.This issue affects Advant MOD 300 AdvaBuild: from 3.0 through 3.7 SP2.

Jul 23, 2024
8.8
CVE-2024-4007HIGH

Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.

Jul 1, 2024
8.8
CVE-2023-0863HIGH

Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC wallbox (JP).This issue affects Terra AC wallbox (UL40/80A): from 1.0;0 through 1.5.5; Terra AC wallbox (UL32A) : from 1.0;0 through 1.6.5; Terra AC wallbox (CE) (Terra AC MID): from 1.0;0 through 1.6.5; Terra AC wallbox (CE) Terra AC Juno CE: from 1.0;0 through 1.6.5; Terra AC wallbox (CE) Terra AC PTB : from 1.0;0 through 1.5.25; Terra AC wallbox (CE) Symbiosis: from 1.0;0 through 1.2.7; Terra AC wallbox (JP): from 1.0;0 through 1.6.5.

May 17, 2023
8.8
CVE-2023-0228HIGH

Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.

Mar 2, 2023
8.8
CVE-2020-8477HIGH

The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.

Apr 22, 2020
8.8
CVE-2020-8997HIGH

Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to enable write access to memory via a specific NFC unlock command. NOTE: The vulnerability is not present in the FreeStyle Libre 14-day in the U.S (announced in August 2018) and FreeStyle Libre 2 outside the U.S (announced in October 2018).

Feb 16, 2020
8.8
CVE-2019-10995HIGH

ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the HMI interface.

Jan 14, 2020
8.8
CVE-2019-7225HIGH

The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface and Tags (MODBUS coils) mapping to the HMI. These credentials are the idal123 password for the IdalMaster account, and the exor password for the exor account. These credentials are used over both HTTP(S) and FTP. There is no option to disable or change these undocumented credentials. An attacker can use these credentials to login to ABB HMI to read/write HMI configuration files and also to reset the device. This affects ABB CP635 HMI, CP600 HMIClient, Panel Builder 600, IDAL FTP server, IDAL HTTP server, and multiple other HMI components.

Jun 27, 2019
8.8
CVE-2019-7226HIGH

The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. Specifically, /cgi/loginDefaultUser creates a session in an authenticated state and returns the session ID along with what may be the username and cleartext password of the user. An attacker can then supply an IDALToken value in a cookie, which will allow them to perform privileged operations such as restarting the service with /cgi/restart. A GET request to /cgi/loginDefaultUser may result in "1 #S_OK IDALToken=532c8632b86694f0232a68a0897a145c admin admin" or a similar response.

Jun 27, 2019
8.8
CVE-2019-7228HIGH

The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.

Jun 27, 2019
8.8
CVE-2019-7232HIGH

The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value overflows a buffer and overwrites a Structured Exception Handler (SEH) address. An unauthenticated attacker can submit a Host header value of 2047 bytes or more to overflow the buffer and overwrite the SEH address, which can then be leveraged to execute attacker-controlled code on the server.

Jun 24, 2019
8.8
CVE-2019-7230HIGH

The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.

Jun 24, 2019
8.8
CVE-2018-13793HIGH

Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 exist in Web Verification, Web Scanning, Web Capture, Monitoring and Administration, and Login.

Jul 9, 2018
8.8
CVE-2017-7906HIGH

In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.

Jun 6, 2018
8.8
CVE-2017-12712HIGH

The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, which involves an authentication key and time stamp, can be compromised or bypassed, which may allow a nearby attacker to issue unauthorized commands to the pacemaker via RF communications. CVSS v3 base score: 7.5, CVSS vector string: AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. Abbott has developed a firmware update to help mitigate the identified vulnerabilities.

Apr 25, 2018
8.8
CVE-2017-17888HIGH

cgi-bin/write.cgi in Anti-Web through 3.8.7, as used on NetBiter / HMS, Ouman EH-net, Alliance System WS100 --> AWU 500, Sauter ERW100F001, Carlo Gavazzi SIU-DLG, AEDILIS SMART-1, SYXTHSENSE WebBiter, ABB SREA, and ASCON DY WebServer devices, allows remote authenticated users to execute arbitrary OS commands via crafted multipart/form-data content, a different vulnerability than CVE-2017-9097.

Dec 27, 2017
8.8
CVE-2017-16731HIGH

An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to LDAP/AD using the LDAP protocol. An attacker could exploit the vulnerability by sniffing local network traffic, allowing the discovery of authentication credentials.

Dec 20, 2017
8.8
CVE-2017-6328HIGH

The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF attack attempts to exploit the trust that a specific website has in a user's browser.

Aug 11, 2017
8.8
CVE-2023-0426HIGH

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product inaccessible. Stack-based Buffer Overflow vulnerability in ABB Freelance controllers AC 700F (conroller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects:  Freelance controllers AC 700F:  from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019 , through Freelance 2019 SP1, through Freelance 2019 SP1 FP1;  Freelance controllers AC 900F:  through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.

Aug 7, 2023
8.6
CVE-2023-0425HIGH

ABB is aware of vulnerabilities in the product versions listed below. An update is available that resolves the reported vulnerabilities in the product versions under maintenance. An attacker who successfully exploited one or more of these vulnerabilities could cause the product to stop or make the product inaccessible.  Numeric Range Comparison Without Minimum Check vulnerability in ABB Freelance controllers AC 700F (Controller modules), ABB Freelance controllers AC 900F (controller modules).This issue affects: Freelance controllers AC 700F:  from 9.0;0 through V9.2 SP2, through Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1;  Freelance controllers AC 900F:  Freelance 2013, through Freelance 2013SP1, through Freelance 2016, through Freelance 2016SP1, through Freelance 2019, through Freelance 2019 SP1, through Freelance 2019 SP1 FP1.

Aug 7, 2023
8.6
CVE-2020-24685HIGH

An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR LED flashing red), physical access to the PLC is required in order to restart the application. This issue affects: ABB AC500 V2 products with onboard Ethernet version 2.8.4 and prior versions.

Feb 9, 2021
8.6
CVE-2025-13779HIGH

Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

Mar 13, 2026
8.3
CVE-2025-13777HIGH

Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This issue affects AWIN GW100 rev.2: 2.0-0, 2.0-1; AWIN GW120: 1.2-0, 1.2-1.

Mar 13, 2026
8.3
CVE-2019-7229HIGH

The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity checks against the new firmware HMI software binary files.

Jun 24, 2019
8.3
CVE-2024-51544HIGH

Service Control vulnerabilities allow access to service restart requests and vm configuration settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
8.2
CVE-2024-51543HIGH

Information Disclosure vulnerabilities allow access to application configuration information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
8.2
CVE-2024-51542HIGH

Configuration Download vulnerabilities allow access to dependency configuration information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
8.2
CVE-2024-51541HIGH

Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
8.2
CVE-2024-48847HIGH

MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes.  Affected products: ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01; MATRIX Series v3.08.01

Dec 5, 2024
8.2
CVE-2025-14510HIGH

Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This issue affects ABB Ability OPTIMAX: 6.1, 6.2, from 6.3.0 before 6.3.1-251120, from 6.4.0 before 6.4.1-251120.

Jan 16, 2026
8.1
CVE-2022-34838HIGH

Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the end user.

Aug 24, 2022
8.1
CVE-2022-0902HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node.

Jul 21, 2022
8.1
CVE-2021-22291HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.

Oct 7, 2025
8.0
CVE-2025-3394HIGH

Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

Apr 30, 2025
7.8
CVE-2024-5402HIGH

Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an executable file in the path of the affected service. This issue affects Mint Workbench I versions: from 5866 before 5868.

Jul 15, 2024
7.8
CVE-2023-0635HIGH

Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Privilege Escalation.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.01; NEXUS Series: from 3.0;0 before 3.07.01; MATRIX Series: from 3.0;0 before 3.07.01.

Jun 5, 2023
7.8
CVE-2022-0010HIGH

Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to exploit this vulnerability to gain control of system nodes. This issue affects QCS 800xA: from 1.0;0 through 6.1SP2; QCS AC450: from 1.0;0 through 5.1SP2; Platform Engineering Tools: from 1.0:0 through 2.3.0.

May 22, 2023
7.8
CVE-2022-29483HIGH

Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.

Jun 2, 2022
7.8
CVE-2019-20383HIGH

ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges by local users via manipulations involving files and using symbolic links.

Aug 13, 2020
7.8
CVE-2020-8482HIGH

Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data

May 29, 2020
7.8
CVE-2019-5621HIGH

ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow.

Apr 29, 2020
7.8
CVE-2020-8489HIGH

Insufficient protection of the inter-process communication functions in ABB System 800xA Information Management (all published versions) enables an attacker authenticated on the local system to inject data, affecting the runtime values to be stored in the archive, or making Information Management history services unavailable.

Apr 29, 2020
7.8
CVE-2020-8488HIGH

Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Management (all published versions) enables an attacker authenticated on the local system to inject data, affecting User Interface update during batch execution and/or compare/printing functionalities.

Apr 29, 2020
7.8
CVE-2020-8485HIGH

Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300 (all published versions) enables an attacker authenticated on the local system to inject data, allowing reads and writes to the controllers or cause windows processes to crash.

Apr 29, 2020
7.8
CVE-2020-8484HIGH

Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (all published versions) enables an attacker authenticated on the local system to inject data, allowing reads and writes to the controllers or cause windows processes to crash.

Apr 29, 2020
7.8
CVE-2020-8471HIGH

For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 and 6.2, AdvaBuild 3.7 SP1 and SP2, OPCServer for MOD 300 (non-800xA) 1.4, OPC Data Link 2.1 and 2.2, Knowledge Manager 8.0, 9.0 and 9.1, Manufacturing Operations Management 1812 and 1909, weak file permissions allow an authenticated attacker to block the license handling, escalate his/her privileges and execute arbitrary code.

Apr 29, 2020
7.8
CVE-2020-8474HIGH

Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction.

Apr 22, 2020
7.8
CVE-2018-19008HIGH

The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser of the Text Editor wherein the application doesn't properly prevent the insertion of specially crafted files which could allow arbitrary code execution.

Feb 13, 2019
7.8
CVE-2018-10616HIGH

ABB Panel Builder 800 all versions has an improper input validation vulnerability which may allow an attacker to insert and run arbitrary code on a computer where the affected product is used.

Jul 18, 2018
7.8
CVE-2018-1168HIGH

This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the access controls for the installed product files. The installation procedure leaves critical files open to manipulation by any authenticated user. An attacker can leverage this vulnerability to escalate privileges to SYSTEM. Was ZDI-CAN-5097.

Feb 21, 2018
7.8
CVE-2024-48844HIGH

Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
7.7
CVE-2024-48843HIGH

Denial of Service vulnerabilities where found providing a potiential for device service disruptions.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
7.7
CVE-2021-35529HIGH

Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids Retail Operations and Counterparty Settlement Billing (CSB) allows an attacker or unauthorized user to access database credentials, shut down the product and access or alter. This issue affects: Hitachi ABB Power Grids Retail Operations version 5.7.2 and prior versions. Hitachi ABB Power Grids Counterparty Settlement Billing (CSB) version 5.7.2 and prior versions.

Aug 20, 2021
7.7
CVE-2012-1801HIGH

Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, WebWare SDK, Interlink Module, S4 OPC Server, QuickTeach, RobotStudio S4, and RobotStudio Lite allow remote attackers to execute arbitrary code via crafted input data.

Apr 18, 2012
7.7
CVE-2019-19094HIGH

Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.

Apr 2, 2020
7.6
CVE-2025-8754HIGH

Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue affects ABB AbilityTM zenon: from 7.50 through 14.

Aug 13, 2025
7.5
CVE-2025-6073HIGH

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and user/password broker authentication is enabled, and CVE-2025-6074 is exploited, the attacker can overflow the buffer for username or password. This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.

Jul 3, 2025
7.5
CVE-2025-6072HIGH

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and CVE-2025-6074 is exploited, the attacker can use the JSON configuration to overflow the date of expiration field.This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.

Jul 3, 2025
7.5
CVE-2024-51546HIGH

Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
7.5
CVE-2024-11316HIGH

Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
7.5
CVE-2024-0335HIGH

ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst) This issue affects Symphony Plus S+ Operations: from 3..0;0 through 3.3 SP1 RU4, from 2.1;0 through 2.1 SP2 RU3, from 2.0;0 through 2.0 SP6 TC6; Symphony Plus S+ Engineering: from 2.1 through 2.3 RU3; Symphony Plus S+ Analyst: from 7.0.0.0 through 7.2.0.2.

Apr 3, 2024
7.5
CVE-2021-22277HIGH

Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service.

Apr 1, 2022
7.5
CVE-2021-22288HIGH

Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive.

Feb 4, 2022
7.5
CVE-2021-22286HIGH

Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive.

Feb 4, 2022
7.5
CVE-2021-22285HIGH

Improper Handling of Exceptional Conditions, Improper Check for Unusual or Exceptional Conditions vulnerability in the ABB SPIET800 and PNI800 module that allows an attacker to cause the denial of service or make the module unresponsive.

Feb 4, 2022
7.5
CVE-2021-35527HIGH

Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids eSOMS allows attacker to gain access to user credentials that are stored by the browser. This issue affects: Hitachi ABB Power Grids eSOMS version 6.3 and prior versions.

Jul 14, 2021
7.5
CVE-2021-27196HIGH

Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as the IP addresses of the different IEC 61850 access points (of IEDs/products), to force the device to reboot, which renders the device inoperable for approximately 60 seconds. This vulnerability affects only products with IEC 61850 interfaces. This issue affects: Hitachi ABB Power Grids Relion 670 Series 1.1; 1.2.3 versions prior to 1.2.3.20; 2.0 versions prior to 2.0.0.13; 2.1; 2.2.2 versions prior to 2.2.2.3; 2.2.3 versions prior to 2.2.3.2. Hitachi ABB Power Grids Relion 670/650 Series 2.2.0 versions prior to 2.2.0.13. Hitachi ABB Power Grids Relion 670/650/SAM600-IO 2.2.1 versions prior to 2.2.1.6. Hitachi ABB Power Grids Relion 650 1.1; 1.2; 1.3 versions prior to 1.3.0.7. Hitachi ABB Power Grids REB500 7.3; 7.4; 7.5; 7.6; 8.2; 8.3. Hitachi ABB Power Grids RTU500 Series 7.x version 7.x and prior versions; 8.x version 8.x and prior versions; 9.x version 9.x and prior versions; 10.x version 10.x and prior versions; 11.x version 11.x and prior versions; 12.x version 12.x and prior versions. Hitachi ABB Power Grids FOX615 (TEGO1) R1D02 version R1D02 and prior versions. Hitachi ABB Power Grids MSM 2.1.0 versions prior to 2.1.0. Hitachi ABB Power Grids GMS600 1.3.0 version 1.3.0 and prior versions. Hitachi ABB Power Grids PWC600 1.0 versions prior to 1.0.1.4; 1.1 versions prior to 1.1.0.1.

Jun 14, 2021
7.5
CVE-2021-26845HIGH

Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain access to report data if the URL used to access the report is discovered. This issue affects: Hitachi ABB Power Grids eSOMS 6.0 versions prior to 6.0.4.2.2; 6.1 versions prior to 6.1.4; 6.3 versions prior to 6.3.

Jun 14, 2021
7.5
CVE-2020-24686HIGH

The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempts to login to the PLC while this vulnerability is exploited, the PLC will show an error state and refuse connections to Automation Builder. The execution of the PLC application is not affected by this vulnerability. This issue affects ABB AC500 V2 products with onboard Ethernet.

Feb 26, 2021
7.5
CVE-2018-20720HIGH

ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot) via a reboot command in an SPA message.

Jan 16, 2019
7.5
CVE-2018-1000531HIGH

inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can result in an incorrect signature validation of a JWT token. This attack can be exploitable when an attacker crafts a JWT token with a valid header using 'none' as algorithm and a body to requests it be validated. This vulnerability was fixed after commit abb0d479389a2509f939452a6767dc424bb5e6ba.

Jun 26, 2018
7.5
CVE-2017-7920HIGH

An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access internal information about status and connected devices without authenticating.

Aug 7, 2017
7.5
CVE-2016-4526HIGH

ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.

Sep 19, 2016
7.5
CVE-2010-0985HIGH

Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

Mar 16, 2010
7.5
CVE-2025-9970HIGH

Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.4.9.21.

Oct 8, 2025
7.4
CVE-2024-9876HIGH

: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4.

Apr 30, 2025
7.3
CVE-2020-8473HIGH

Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low privileged users to read, modify, add and delete system and application files. An authenticated attacker who successfully exploit the vulnerabilities could escalate his/her privileges, cause system functions to stop and to corrupt user applications.

Apr 29, 2020
7.3
CVE-2019-7227HIGH

In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP server functionality to download and upload files. An unauthenticated attacker can take advantage of the hardcoded or default credential pair exor/exor to become an authenticated attacker.

Jun 27, 2019
7.3
CVE-2025-10207HIGH

Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5.

Sep 18, 2025
7.2
CVE-2024-48851HIGH

Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution is possible due to an improper input validation. This issue affects FLXEON: through 9.3.5.

Sep 18, 2025
7.2
CVE-2023-0636HIGH

Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021, 2CQG100112R2021, 2CQG100103R2021, 2CQG100107R2021, 2CQG100108R2021, 2CQG100109R2021, 2CQG100111R2021, 2CQG100113R2021 modules), ABB Ltd. MATRIX Series on MATRIX Series, Linux (2CQG100102R1021, 2CQG100103R1021, 2CQG100104R1021, 2CQG100105R1021, 2CQG100106R1021 modules) allows Command Injection.This issue affects ASPECT®-Enterprise: from 3.0;0 before 3.07.0; NEXUS Series: from 3.0;0 before 3.07.0; MATRIX Series: from 3.0;0 before 3.07.1.

Jun 5, 2023
7.2
CVE-2016-2281HIGH

Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

Mar 18, 2016
7.2
CVE-2025-3465HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM, ABB CoreSense™ M10.This issue affects CoreSense™ HM: through 2.3.1; CoreSense™ M10: through 1.4.1.12.

Oct 20, 2025
7.1
CVE-2025-3395HIGH

Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.

Apr 30, 2025
7.1
CVE-2024-48846HIGH

Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
7.1
CVE-2023-0864HIGH

Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC wallbox (JP).This issue affects Terra AC wallbox (UL40/80A): from 1.0;0 through 1.5.5; Terra AC wallbox (UL32A) : from 1.0;0 through 1.6.5; Terra AC wallbox (CE) (Terra AC MID): from 1.0;0 through 1.6.5; Terra AC wallbox (CE) Terra AC Juno CE: from 1.0;0 through 1.6.5; Terra AC wallbox (CE) Terra AC PTB : from 1.0;0 through 1.5.25; Terra AC wallbox (CE) Symbiosis: from 1.0;0 through 1.2.7; Terra AC wallbox (JP): from 1.0;0 through 1.6.5.

May 17, 2023
7.1
CVE-2019-18998HIGH

Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.

Feb 17, 2020
7.1
CVE-2019-18996HIGH

Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the execution of code in the application’s context.

Dec 18, 2019
7.1
CVE-2024-48842HIGH

Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 and newer versions

Sep 17, 2025
7.0
CVE-2023-3322HIGH

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.

Jul 24, 2023
7.0
CVE-2023-3321HIGH

A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects ABB Ability™ zenon: from 11 build through 11 build 106404.

Jul 24, 2023
7.0
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2012-0245HIGH
10.0
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime befo…Mar 9, 2012›
CVE-2008-2474HIGH
10.0
Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 a…Sep 29, 2008›
CVE-2013-5021HIGH
9.3
Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in Nation…Aug 6, 2013›
CVE-2026-32059HIGH
8.8
OpenClaw version 2026.2.22-2 prior to 2026.2.23 tools.exec.safeBins validation for sort command fail…Mar 11, 2026›
CVE-2025-4676HIGH
8.8
Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValu…Jan 7, 2026›
CVE-2025-10205HIGH
8.8
Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON:…Sep 17, 2025›
CVE-2024-45044HIGH
8.8
Bareos is open source software for backup, archiving, and recovery of data for operating systems. Wh…Sep 10, 2024›
CVE-2020-11640HIGH
8.8
AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the com…Jul 23, 2024›
CVE-2024-4007HIGH
8.8
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows…Jul 1, 2024›
CVE-2023-0863HIGH
8.8
Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32…May 17, 2023›
CVE-2023-0228HIGH
8.8
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony…Mar 2, 2023›
CVE-2020-8477HIGH
8.8
The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wron…Apr 22, 2020›
CVE-2020-8997HIGH
8.8
Older generation Abbott FreeStyle Libre sensors allow remote attackers within close proximity to ena…Feb 16, 2020›
CVE-2019-10995HIGH
8.8
ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts th…Jan 14, 2020›
CVE-2019-7225HIGH
8.8
The ABB HMI components implement hidden administrative accounts that are used during the provisionin…Jun 27, 2019›
CVE-2019-7226HIGH
8.8
The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to byp…Jun 27, 2019›
CVE-2019-7228HIGH
8.8
The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication…Jun 27, 2019›
CVE-2019-7232HIGH
8.8
The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web…Jun 24, 2019›
CVE-2019-7230HIGH
8.8
The ABB IDAL FTP server mishandles format strings in a username during the authentication process. A…Jun 24, 2019›
CVE-2018-13793HIGH
8.8
Multiple Cross Site Request Forgery (CSRF) vulnerabilities in the HTTP API in ABBYY FlexiCapture bef…Jul 9, 2018›
CVE-2017-7906HIGH
8.8
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was per…Jun 6, 2018›
CVE-2017-12712HIGH
8.8
The authentication algorithm in Abbott Laboratories pacemakers manufactured prior to Aug 28, 2017, w…Apr 25, 2018›
CVE-2017-17888HIGH
8.8
cgi-bin/write.cgi in Anti-Web through 3.8.7, as used on NetBiter / HMS, Ouman EH-net, Alliance Syste…Dec 27, 2017›
CVE-2017-16731HIGH
8.8
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 …Dec 20, 2017›
CVE-2017-6328HIGH
8.8
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forger…Aug 11, 2017›
CVE-2023-0426HIGH
8.6
ABB is aware of vulnerabilities in the product versions listed below. An update is available that r…Aug 7, 2023›
CVE-2023-0425HIGH
8.6
ABB is aware of vulnerabilities in the product versions listed below. An update is available that r…Aug 7, 2023›
CVE-2020-24685HIGH
8.6
An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial…Feb 9, 2021›
CVE-2025-13779HIGH
8.3
Missing authentication for critical function vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.T…Mar 13, 2026›
CVE-2025-13777HIGH
8.3
Authentication bypass by capture-replay vulnerability in ABB AWIN GW100 rev.2, ABB AWIN GW120.This i…Mar 13, 2026›
CVE-2019-7229HIGH
8.3
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software c…Jun 24, 2019›
CVE-2024-51544HIGH
8.2
Service Control vulnerabilities allow access to service restart requests and vm configuration settin…Dec 5, 2024›
CVE-2024-51543HIGH
8.2
Information Disclosure vulnerabilities allow access to application configuration information.  Affec…Dec 5, 2024›
CVE-2024-51542HIGH
8.2
Configuration Download vulnerabilities allow access to dependency configuration information.  Affect…Dec 5, 2024›
CVE-2024-51541HIGH
8.2
Local File Inclusion vulnerabilities allow access to sensitive system information.  Affected product…Dec 5, 2024›
CVE-2024-48847HIGH
8.2
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application depe…Dec 5, 2024›
CVE-2025-14510HIGH
8.1
Incorrect Implementation of Authentication Algorithm vulnerability in ABB ABB Ability OPTIMAX.This i…Jan 16, 2026›
CVE-2022-34838HIGH
8.1
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who suc…Aug 24, 2022›
CVE-2022-0902HIGH
8.1
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralizat…Jul 21, 2022›
CVE-2021-22291HIGH
8.0
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerab…Oct 7, 2025›
CVE-2025-3394HIGH
7.8
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This i…Apr 30, 2025›
CVE-2024-5402HIGH
7.8
Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who success…Jul 15, 2024›
CVE-2023-0635HIGH
7.8
Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Li…Jun 5, 2023›
CVE-2022-0010HIGH
7.8
Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB …May 22, 2023›
CVE-2022-29483HIGH
7.8
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious sof…Jun 2, 2022›
CVE-2019-20383HIGH
7.8
ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows esca…Aug 13, 2020›
CVE-2020-8482HIGH
7.8
Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6…May 29, 2020›
CVE-2019-5621HIGH
7.8
ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer…Apr 29, 2020›
CVE-2020-8489HIGH
7.8
Insufficient protection of the inter-process communication functions in ABB System 800xA Information…Apr 29, 2020›
CVE-2020-8488HIGH
7.8
Insufficient protection of the inter-process communication functions in ABB System 800xA Batch Manag…Apr 29, 2020›
CVE-2020-8485HIGH
7.8
Insufficient protection of the inter-process communication functions in ABB System 800xA for MOD 300…Apr 29, 2020›
CVE-2020-8484HIGH
7.8
Insufficient protection of the inter-process communication functions in ABB System 800xA for DCI (al…Apr 29, 2020›
CVE-2020-8471HIGH
7.8
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and relate…Apr 29, 2020›
CVE-2020-8474HIGH
7.8
Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify reg…Apr 22, 2020›
CVE-2018-19008HIGH
7.8
The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability …Feb 13, 2019›
CVE-2018-10616HIGH
7.8
ABB Panel Builder 800 all versions has an improper input validation vulnerability which may allow an…Jul 18, 2018›
CVE-2018-1168HIGH
7.8
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB …Feb 21, 2018›
CVE-2024-48844HIGH
7.7
Denial of Service vulnerabilities where found providing a potiential for device service disruptions.…Dec 5, 2024›
CVE-2024-48843HIGH
7.7
Denial of Service vulnerabilities where found providing a potiential for device service disruptions.…Dec 5, 2024›
CVE-2021-35529HIGH
7.7
Insufficiently Protected Credentials vulnerability in client environment of Hitachi ABB Power Grids …Aug 20, 2021›
CVE-2012-1801HIGH
7.7
Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, Web…Apr 18, 2012›
CVE-2019-19094HIGH
7.6
Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL …Apr 2, 2020›
CVE-2025-8754HIGH
7.5
Missing Authentication for Critical Function vulnerability in ABB ABB AbilityTM zenon.This issue aff…Aug 13, 2025›
CVE-2025-6073HIGH
7.5
Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface…Jul 3, 2025›
CVE-2025-6072HIGH
7.5
Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interfa…Jul 3, 2025›
CVE-2024-51546HIGH
7.5
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles.  Affected p…Dec 5, 2024›
CVE-2024-11316HIGH
7.5
Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the produ…Dec 5, 2024›
CVE-2024-0335HIGH
7.5
ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API componen…Apr 3, 2024›
CVE-2021-22277HIGH
7.5
Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder …Apr 1, 2022›
CVE-2021-22288HIGH
7.5
Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to …Feb 4, 2022›
CVE-2021-22286HIGH
7.5
Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to …Feb 4, 2022›
CVE-2021-22285HIGH
7.5
Improper Handling of Exceptional Conditions, Improper Check for Unusual or Exceptional Conditions vu…Feb 4, 2022›
CVE-2021-35527HIGH
7.5
Password autocomplete vulnerability in the web application password field of Hitachi ABB Power Grids…Jul 14, 2021›
CVE-2021-27196HIGH
7.5
Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650…Jun 14, 2021›
CVE-2021-26845HIGH
7.5
Information Exposure vulnerability in Hitachi ABB Power Grids eSOMS allows unauthorized user to gain…Jun 14, 2021›
CVE-2020-24686HIGH
7.5
The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and…Feb 26, 2021›
CVE-2018-20720HIGH
7.5
ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remot…Jan 16, 2019›
CVE-2018-1000531HIGH
7.5
inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-…Jun 26, 2018›
CVE-2017-7920HIGH
7.5
An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and p…Aug 7, 2017›
CVE-2016-4526HIGH
7.5
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in…Sep 19, 2016›
CVE-2010-0985HIGH
7.5
Directory traversal vulnerability in the Abbreviations Manager (com_abbrev) component 1.1 for Joomla…Mar 16, 2010›
CVE-2025-9970HIGH
7.4
Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects…Oct 8, 2025›
CVE-2024-9876HIGH
7.3
: Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.Th…Apr 30, 2025›
CVE-2020-8473HIGH
7.3
Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and e…Apr 29, 2020›
CVE-2019-7227HIGH
7.3
In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the h…Jun 27, 2019›
CVE-2025-10207HIGH
7.2
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON…Sep 18, 2025›
CVE-2024-48851HIGH
7.2
Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.A remote code execution i…Sep 18, 2025›
CVE-2023-0636HIGH
7.2
Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux …Jun 5, 2023›
CVE-2016-2281HIGH
7.2
Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileg…Mar 18, 2016›
CVE-2025-3465HIGH
7.1
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB …Oct 20, 2025›
CVE-2025-3395HIGH
7.1
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vu…Apr 30, 2025›
CVE-2024-48846HIGH
7.1
Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive…Dec 5, 2024›
CVE-2023-0864HIGH
7.1
Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), AB…May 17, 2023›
CVE-2019-18998HIGH
7.1
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior t…Feb 17, 2020›
CVE-2019-18996HIGH
7.1
Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier a…Dec 18, 2019›
CVE-2024-48842HIGH
7.0
Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5 a…Sep 17, 2025›
CVE-2023-3322HIGH
7.0
A vulnerability exists by allowing low-privileged users to read and update the data in various dire…Jul 24, 2023›
CVE-2023-3321HIGH
7.0
A vulnerability exists by allowing low-privileged users to read and update the data in various dire…Jul 24, 2023›