Vulnerabilidades em ABB

220 resultados
Análise Vexday

O portfólio de vulnerabilidades da ABB acumula 218 CVEs catalogadas, das quais 35 são classificadas como críticas e 12 contam com prova de conceito pública disponível, o que representa exposição técnica concreta para equipes de defesa. A taxa de exploração ativa está abaixo da média geral do catálogo KEV, com zero registros confirmados de exploração ativa — dado positivo, mas que não elimina o risco representado por falhas com PoC conhecida. A CVE mais perigosa no cenário atual é CVE-2019-5620, com score EPSS de 0,70, indicando probabilidade relevante de exploração nos próximos 30 dias e merecendo atenção prioritária de patch management. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão estrutural que sugere a necessidade de revisão de práticas de sanitização de dados em múltiplos componentes do portfólio.

CVE-2019-19089MEDIUMeSOMS: X-Content-Type-Options Header MissingEPSS 1.1%CVE-2021-22288HIGHSECURITY – Denial of Service Vulnerabilities in SPIET800 INFI-Net to Ethernet Transfer module and PNI800 S+ Ethernet communication interface moduleEPSS 1.1%CVE-2021-22286HIGHSECURITY – Denial of Service Vulnerabilities in SPIET800 INFI-Net to Ethernet Transfer module and PNI800 S+ Ethernet communication interface moduleEPSS 1.1%CVE-2021-22285HIGHSECURITY – Denial of Service Vulnerabilities in SPIET800 INFI-Net to Ethernet Transfer module and PNI800 S+ Ethernet communication interface moduleEPSS 1.0%CVE-2024-13946HIGHBinary Planting / LoadLibrary DLL's not SignedEPSS 1.0%CVE-2021-22277HIGHAC 800M MMS - Denial of Service vulnerability in MMS communicationEPSS 0.9%CVE-2019-19094HIGHABB eSOMS: SQL injection vulnerabilityEPSS 0.9%CVE-2024-48849HIGHAuthentication and Authorization IssuesEPSS 0.9%CVE-2024-48844HIGHDenial of Service, DoSEPSS 0.9%CVE-2022-0947CRITICALArctic Wireless Gateway Firewall vulnerabilityEPSS 0.9%CVE-2019-19093MEDIUMABB eSOMS: Password complexity issueEPSS 0.9%CVE-2021-22284HIGHSECURITY - OPC Server for AC 800M - Remote Code Execution VulnerabilityEPSS 0.8%CVE-2019-19092LOWABB eSOMS: Viewstate without MAC SignatureEPSS 0.8%CVE-2019-19002MEDIUMABB eSOMS X-XSS-Protection not enabledEPSS 0.8%CVE-2019-19003MEDIUMABB eSOMS: HTTPOnly flag not setEPSS 0.8%CVE-2019-18998HIGHAsset Suite Direct Object Reference AccessEPSS 0.8%CVE-2025-9574CRITICALMissing Authentication VulnerabilityEPSS 0.8%CVE-2018-17926The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicioEPSS 0.8%CVE-2019-19091MEDIUMABB eSOMS: HTTP response information leakageEPSS 0.8%CVE-2024-1914MEDIUMAn attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vEPSS 0.7%