Записи ABB
162 опубликованных записей вендора abb.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 3,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls11
- CWE-20 Improper Input Validation10
- CWE-287 Improper Authentication9
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-732 Incorrect Permission Assignment for Critical Resource6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
162 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2019-7232Эксплойта нет | The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request.abb · pb610 panel builder 600 firmware · CWE-787 | Высокая8,8 | — | 52,1 % | 24 июн. 2019 г. |
44В плане | CVE-2022-0902Эксплойта нет | ABB Flow Computer and Remote Controllers Path Traversal Vulnerability in Totalflow TCP protocol can lead to root accessabb · rmc-100 firmware · CWE-22 | Критическая9,8 | — | 16,5 % | 21 июл. 2022 г. |
43В плане | CVE-2024-6298Proof of concept | remote code executionabb · aspect-ent-12 firmware · CWE-1287 | Критическая9,4 | — | 19,0 % | 5 июл. 2024 г. |
42В плане | CVE-2024-6209Proof of concept | unauthorized file accessabb · aspect-ent-12 firmware · CWE-552 | Критическая9,4 | — | 17,2 % | 5 июл. 2024 г. |
42В плане | CVE-2012-0245Эксплойта нет | Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Modabb · interlink module · CWE-119 | Критическая10,0 | — | 8,2 % | 9 мар. 2012 г. |
42В плане | CVE-2008-2474Эксплойта нет | Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitrabb · pcu400 · CWE-119 | Критическая10,0 | — | 7,9 % | 29 сент. 2008 г. |
40В плане | CVE-2018-18995Эксплойта нет | Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrativabb · gate-e1 firmware · CWE-306 | Критическая9,8 | — | 2,6 % | 3 янв. 2019 г. |
40В плане | CVE-2017-9664Эксплойта нет | In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker abb · srea-50 firmware · CWE-23 | Критическая9,8 | — | 2,6 % | 24 мая 2018 г. |
40В плане | CVE-2017-7931Эксплойта нет | In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acceabb · ip gateway firmware · CWE-287 | Критическая9,8 | — | 2,5 % | 6 июн. 2018 г. |
40В плане | CVE-2020-8479Эксплойта нет | ABB Central Licensing System - XML External Entity Injectionabb · 800xa system · CWE-91 | Критическая9,8 | — | 2,3 % | 28 апр. 2020 г. |
40В плане | CVE-2020-24679Эксплойта нет | Denial of Service attack on Symphony Plusabb · symphony \+ historian · CWE-20 | Критическая9,8 | — | 1,9 % | 22 дек. 2020 г. |
40В плане | CVE-2020-8481Эксплойта нет | ABB Central Licensing System - Information disclosureabb · 800xa system · CWE-200 | Критическая9,8 | — | 1,9 % | 28 апр. 2020 г. |
40В плане | CVE-2019-18250Эксплойта нет | In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication babb · plant connect · CWE-288 | Критическая9,8 | — | 1,7 % | 25 нояб. 2019 г. |
39Наблюдать | CVE-2024-51544Эксплойта нет | Service Control vulnerabilities allow access to service restart requests and vm configuration settings.abb · aspect-ent-12 firmware · CWE-15 | Высокая8,8 | — | 13,2 % | 5 дек. 2024 г. |
39Наблюдать | CVE-2017-7933Эксплойта нет | In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unautabb · ip gateway firmware · CWE-522 | Критическая9,8 | — | 1,7 % | 6 июн. 2018 г. |
39Наблюдать | CVE-2020-24683Эксплойта нет | Authentication Bypass in Symphony Plusabb · symphony \+ historian · CWE-305 | Критическая9,8 | — | 1,5 % | 22 дек. 2020 г. |
39Наблюдать | CVE-2021-22279Эксплойта нет | OmniCore RobotWare Missing Authentication Vulnerabilityabb · omnicore c30 firmware · CWE-306 | Критическая9,8 | — | 1,4 % | 13 дек. 2021 г. |
39Наблюдать | CVE-2020-10288Эксплойта нет | RVD#3327: No authentication required for accesing ABB IRC5 FTP serverabb · robotware · CWE-284 | Критическая9,8 | — | 1,4 % | 15 июл. 2020 г. |
39Наблюдать | CVE-2020-10287Эксплойта нет | RVD#3326: Hardcoded default credentials on IRC 5 OPC Serverabb · irb140 firmware · CWE-255 | Критическая9,8 | — | 1,4 % | 15 июл. 2020 г. |
39Наблюдать | CVE-2019-19104Эксплойта нет | ABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access Controlabb · tg\/s3.2 firmware · CWE-287 | Критическая9,8 | — | 1,4 % | 22 апр. 2020 г. |
39Наблюдать | CVE-2023-0636Эксплойта нет | Remote Code Execution via Command Injectionabb · aspect-ent-2 firmware · CWE-77 | Критическая9,8 | — | 1,4 % | 5 июн. 2023 г. |
39Наблюдать | CVE-2020-24675Эксплойта нет | Weak Authentication in Symphony Plusabb · symphony \+ historian · CWE-287 | Критическая9,8 | — | 1,2 % | 22 дек. 2020 г. |
39Наблюдать | CVE-2020-24673Эксплойта нет | SQL Injection in Symphony Plusabb · symphony \+ historian · CWE-89 | Критическая9,8 | — | 1,1 % | 22 дек. 2020 г. |
39Наблюдать | CVE-2022-0947Эксплойта нет | Arctic Wireless Gateway Firewall vulnerabilityabb · arg600a1220na firmware · CWE-665 | Критическая9,8 | — | 0,9 % | 10 мая 2022 г. |
39Наблюдать | CVE-2022-4126Эксплойта нет | Use of Default Passwordabb · rccmd · CWE-1393 | Критическая9,8 | — | 0,6 % | 27 мар. 2023 г. |
- CVE-2019-723251В плане
The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request.
ВысокаяCVSS 8,8Эксплойта нетEPSS 52 %abb · pb610 panel builder 600 firmware24 июн. 2019 г.
- CVE-2022-090244В плане
ABB Flow Computer and Remote Controllers Path Traversal Vulnerability in Totalflow TCP protocol can lead to root access
КритическаяCVSS 9,8Эксплойта нетEPSS 16 %abb · rmc-100 firmware21 июл. 2022 г.
- CVE-2024-629843В плане
remote code execution
КритическаяCVSS 9,4Proof of conceptEPSS 19 %abb · aspect-ent-12 firmware5 июл. 2024 г.
- CVE-2024-620942В плане
unauthorized file access
КритическаяCVSS 9,4Proof of conceptEPSS 17 %abb · aspect-ent-12 firmware5 июл. 2024 г.
- CVE-2012-024542В плане
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Mod
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %abb · interlink module9 мар. 2012 г.
- CVE-2008-247442В плане
Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitr
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %abb · pcu40029 сент. 2008 г.
- CVE-2018-1899540В плане
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrativ
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %abb · gate-e1 firmware3 янв. 2019 г.
- CVE-2017-966440В плане
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %abb · srea-50 firmware24 мая 2018 г.
- CVE-2017-793140В плане
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acce
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %abb · ip gateway firmware6 июн. 2018 г.
- CVE-2020-847940В плане
ABB Central Licensing System - XML External Entity Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %abb · 800xa system28 апр. 2020 г.
- CVE-2020-2467940В плане
Denial of Service attack on Symphony Plus
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %abb · symphony \+ historian22 дек. 2020 г.
- CVE-2020-848140В плане
ABB Central Licensing System - Information disclosure
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %abb · 800xa system28 апр. 2020 г.
- CVE-2019-1825040В плане
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication b
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %abb · plant connect25 нояб. 2019 г.
- CVE-2024-5154439Наблюдать
Service Control vulnerabilities allow access to service restart requests and vm configuration settings.
ВысокаяCVSS 8,8Эксплойта нетEPSS 13 %abb · aspect-ent-12 firmware5 дек. 2024 г.
- CVE-2017-793339Наблюдать
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unaut
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %abb · ip gateway firmware6 июн. 2018 г.
- CVE-2020-2468339Наблюдать
Authentication Bypass in Symphony Plus
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · symphony \+ historian22 дек. 2020 г.
- CVE-2021-2227939Наблюдать
OmniCore RobotWare Missing Authentication Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · omnicore c30 firmware13 дек. 2021 г.
- CVE-2020-1028839Наблюдать
RVD#3327: No authentication required for accesing ABB IRC5 FTP server
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · robotware15 июл. 2020 г.
- CVE-2020-1028739Наблюдать
RVD#3326: Hardcoded default credentials on IRC 5 OPC Server
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · irb140 firmware15 июл. 2020 г.
- CVE-2019-1910439Наблюдать
ABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access Control
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · tg\/s3.2 firmware22 апр. 2020 г.
- CVE-2023-063639Наблюдать
Remote Code Execution via Command Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · aspect-ent-2 firmware5 июн. 2023 г.
- CVE-2020-2467539Наблюдать
Weak Authentication in Symphony Plus
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · symphony \+ historian22 дек. 2020 г.
- CVE-2020-2467339Наблюдать
SQL Injection in Symphony Plus
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · symphony \+ historian22 дек. 2020 г.
- CVE-2022-094739Наблюдать
Arctic Wireless Gateway Firewall vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · arg600a1220na firmware10 мая 2022 г.
- CVE-2022-412639Наблюдать
Use of Default Password
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %abb · rccmd27 мар. 2023 г.