Vulnerabilities in ABB

221 results
Vexday analysis

O portfólio de vulnerabilidades da ABB acumula 218 CVEs catalogadas, das quais 35 são classificadas como críticas e 12 contam com prova de conceito pública disponível, o que representa exposição técnica concreta para equipes de defesa. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com zero registros confirmados de exploração ativa — dado positivo, mas que não elimina o risco representado por falhas com PoC conhecida. A CVE mais perigosa no cenário atual é CVE-2019-5620, com score EPSS de 0,70, indicando probabilidade relevante de exploração nos próximos 30 dias e merecendo atenção prioritária de patch management. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão estrutural que sugere a necessidade de revisão de práticas de sanitização de dados em múltiplos componentes do portfólio.

CVE-2025-14774HIGHCommunication analysis between the Card Reader and TP2CardReaderService daemonEPSS 0.2%CVE-2025-4407MEDIUMApplication does not invalidate session after password resetEPSS 0.2%CVE-2021-22283MEDIUMMMS File Transfer Vulnerability impact on Distribution Automation productsEPSS 0.2%CVE-2024-48842HIGHHardcoded passwordsEPSS 0.2%CVE-2023-2685HIGHUnquoted Service Path in ABB AO-OPCEPSS 0.2%CVE-2023-0864HIGHConfiguration data is exchanged in plaintext and could be available to a nearby attacker if present during configuration or usage of the device via Bluetooth Low Energy (BLE).EPSS 0.2%CVE-2022-34838HIGHABB Ability TM Operations Data Management Zenon Zenon Log Server file access controlEPSS 0.2%CVE-2026-12705MEDIUMIntegrity mechanism of KNX-device FW-files can be bypassed in ABB Update ToolEPSS 0.2%CVE-2024-6157MEDIUMAn attacker who successfully exploited these vulnerabilities could cause the robot to stop. A vulnerability exists in the PROFINET stack EPSS 0.2%CVE-2024-13948MEDIUMInsecure PermissionsEPSS 0.1%CVE-2024-8036MEDIUMUnauthorized Modifications of Firmware and ConfigurationEPSS 0.1%CVE-2022-34837MEDIUMABB Ability TM Operations Data Management Zenon Zenon Log Server file access controlEPSS 0.1%CVE-2025-3394HIGHVulnerability in user management of Automation BuilderEPSS 0.1%CVE-2024-10334HIGHCamera passwords stored in clear textEPSS 0.1%CVE-2021-22278MEDIUMCertificate verification vulnerability in Update Manager of PCM600 Engineering ToolEPSS 0.1%CVE-2020-11639HIGHInsufficient access control on Inter process communication,EPSS 0.1%CVE-2025-13162MEDIUMAdvant Master Online Builder DLL vulnerabilityEPSS 0.1%CVE-2025-7064MEDIUMFreelance Security Lock – Access to Windows OSEPSS 0.1%CVE-2025-9970MEDIUMApplication credential stored in clear text in memoryEPSS 0.1%CVE-2025-3395HIGHIncorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.ThEPSS 0.1%