ABB records
162 published records for vendor abb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 11
- With a fix record
- 3.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls11
- CWE-20 Improper Input Validation10
- CWE-287 Improper Authentication9
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-732 Incorrect Permission Assignment for Critical Resource6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
162 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2019-7232No exploit | The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request.abb · pb610 panel builder 600 firmware · CWE-787 | High8.8 | — | 52.1% | Jun 24, 2019 |
44Plan | CVE-2022-0902No exploit | ABB Flow Computer and Remote Controllers Path Traversal Vulnerability in Totalflow TCP protocol can lead to root accessabb · rmc-100 firmware · CWE-22 | Critical9.8 | — | 16.5% | Jul 21, 2022 |
43Plan | CVE-2024-6298Proof of concept | remote code executionabb · aspect-ent-12 firmware · CWE-1287 | Critical9.4 | — | 19.0% | Jul 5, 2024 |
42Plan | CVE-2024-6209Proof of concept | unauthorized file accessabb · aspect-ent-12 firmware · CWE-552 | Critical9.4 | — | 17.2% | Jul 5, 2024 |
42Plan | CVE-2012-0245No exploit | Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Modabb · interlink module · CWE-119 | Critical10.0 | — | 8.2% | Mar 9, 2012 |
42Plan | CVE-2008-2474No exploit | Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitrabb · pcu400 · CWE-119 | Critical10.0 | — | 7.9% | Sep 29, 2008 |
40Plan | CVE-2018-18995No exploit | Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrativabb · gate-e1 firmware · CWE-306 | Critical9.8 | — | 2.6% | Jan 3, 2019 |
40Plan | CVE-2017-9664No exploit | In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker abb · srea-50 firmware · CWE-23 | Critical9.8 | — | 2.6% | May 24, 2018 |
40Plan | CVE-2017-7931No exploit | In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acceabb · ip gateway firmware · CWE-287 | Critical9.8 | — | 2.5% | Jun 6, 2018 |
40Plan | CVE-2020-8479No exploit | ABB Central Licensing System - XML External Entity Injectionabb · 800xa system · CWE-91 | Critical9.8 | — | 2.3% | Apr 28, 2020 |
40Plan | CVE-2020-24679No exploit | Denial of Service attack on Symphony Plusabb · symphony \+ historian · CWE-20 | Critical9.8 | — | 1.9% | Dec 22, 2020 |
40Plan | CVE-2020-8481No exploit | ABB Central Licensing System - Information disclosureabb · 800xa system · CWE-200 | Critical9.8 | — | 1.9% | Apr 28, 2020 |
40Plan | CVE-2019-18250No exploit | In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication babb · plant connect · CWE-288 | Critical9.8 | — | 1.7% | Nov 25, 2019 |
39Monitor | CVE-2024-51544No exploit | Service Control vulnerabilities allow access to service restart requests and vm configuration settings.abb · aspect-ent-12 firmware · CWE-15 | High8.8 | — | 13.2% | Dec 5, 2024 |
39Monitor | CVE-2017-7933No exploit | In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unautabb · ip gateway firmware · CWE-522 | Critical9.8 | — | 1.7% | Jun 6, 2018 |
39Monitor | CVE-2020-24683No exploit | Authentication Bypass in Symphony Plusabb · symphony \+ historian · CWE-305 | Critical9.8 | — | 1.5% | Dec 22, 2020 |
39Monitor | CVE-2021-22279No exploit | OmniCore RobotWare Missing Authentication Vulnerabilityabb · omnicore c30 firmware · CWE-306 | Critical9.8 | — | 1.4% | Dec 13, 2021 |
39Monitor | CVE-2020-10288No exploit | RVD#3327: No authentication required for accesing ABB IRC5 FTP serverabb · robotware · CWE-284 | Critical9.8 | — | 1.4% | Jul 15, 2020 |
39Monitor | CVE-2020-10287No exploit | RVD#3326: Hardcoded default credentials on IRC 5 OPC Serverabb · irb140 firmware · CWE-255 | Critical9.8 | — | 1.4% | Jul 15, 2020 |
39Monitor | CVE-2019-19104No exploit | ABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access Controlabb · tg\/s3.2 firmware · CWE-287 | Critical9.8 | — | 1.4% | Apr 22, 2020 |
39Monitor | CVE-2023-0636No exploit | Remote Code Execution via Command Injectionabb · aspect-ent-2 firmware · CWE-77 | Critical9.8 | — | 1.4% | Jun 5, 2023 |
39Monitor | CVE-2020-24675No exploit | Weak Authentication in Symphony Plusabb · symphony \+ historian · CWE-287 | Critical9.8 | — | 1.2% | Dec 22, 2020 |
39Monitor | CVE-2020-24673No exploit | SQL Injection in Symphony Plusabb · symphony \+ historian · CWE-89 | Critical9.8 | — | 1.1% | Dec 22, 2020 |
39Monitor | CVE-2022-0947No exploit | Arctic Wireless Gateway Firewall vulnerabilityabb · arg600a1220na firmware · CWE-665 | Critical9.8 | — | 0.9% | May 10, 2022 |
39Monitor | CVE-2022-4126No exploit | Use of Default Passwordabb · rccmd · CWE-1393 | Critical9.8 | — | 0.6% | Mar 27, 2023 |
- CVE-2019-723251Plan
The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request.
HighCVSS 8.8No exploitEPSS 52%abb · pb610 panel builder 600 firmwareJun 24, 2019
- CVE-2022-090244Plan
ABB Flow Computer and Remote Controllers Path Traversal Vulnerability in Totalflow TCP protocol can lead to root access
CriticalCVSS 9.8No exploitEPSS 16%abb · rmc-100 firmwareJul 21, 2022
- CVE-2024-629843Plan
remote code execution
CriticalCVSS 9.4Proof of conceptEPSS 19%abb · aspect-ent-12 firmwareJul 5, 2024
- CVE-2024-620942Plan
unauthorized file access
CriticalCVSS 9.4Proof of conceptEPSS 17%abb · aspect-ent-12 firmwareJul 5, 2024
- CVE-2012-024542Plan
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Mod
CriticalCVSS 10.0No exploitEPSS 8%abb · interlink moduleMar 9, 2012
- CVE-2008-247442Plan
Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitr
CriticalCVSS 10.0No exploitEPSS 8%abb · pcu400Sep 29, 2008
- CVE-2018-1899540Plan
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrativ
CriticalCVSS 9.8No exploitEPSS 3%abb · gate-e1 firmwareJan 3, 2019
- CVE-2017-966440Plan
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker
CriticalCVSS 9.8No exploitEPSS 3%abb · srea-50 firmwareMay 24, 2018
- CVE-2017-793140Plan
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acce
CriticalCVSS 9.8No exploitEPSS 3%abb · ip gateway firmwareJun 6, 2018
- CVE-2020-847940Plan
ABB Central Licensing System - XML External Entity Injection
CriticalCVSS 9.8No exploitEPSS 2%abb · 800xa systemApr 28, 2020
- CVE-2020-2467940Plan
Denial of Service attack on Symphony Plus
CriticalCVSS 9.8No exploitEPSS 2%abb · symphony \+ historianDec 22, 2020
- CVE-2020-848140Plan
ABB Central Licensing System - Information disclosure
CriticalCVSS 9.8No exploitEPSS 2%abb · 800xa systemApr 28, 2020
- CVE-2019-1825040Plan
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication b
CriticalCVSS 9.8No exploitEPSS 2%abb · plant connectNov 25, 2019
- CVE-2024-5154439Monitor
Service Control vulnerabilities allow access to service restart requests and vm configuration settings.
HighCVSS 8.8No exploitEPSS 13%abb · aspect-ent-12 firmwareDec 5, 2024
- CVE-2017-793339Monitor
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unaut
CriticalCVSS 9.8No exploitEPSS 2%abb · ip gateway firmwareJun 6, 2018
- CVE-2020-2468339Monitor
Authentication Bypass in Symphony Plus
CriticalCVSS 9.8No exploitEPSS 1%abb · symphony \+ historianDec 22, 2020
- CVE-2021-2227939Monitor
OmniCore RobotWare Missing Authentication Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%abb · omnicore c30 firmwareDec 13, 2021
- CVE-2020-1028839Monitor
RVD#3327: No authentication required for accesing ABB IRC5 FTP server
CriticalCVSS 9.8No exploitEPSS 1%abb · robotwareJul 15, 2020
- CVE-2020-1028739Monitor
RVD#3326: Hardcoded default credentials on IRC 5 OPC Server
CriticalCVSS 9.8No exploitEPSS 1%abb · irb140 firmwareJul 15, 2020
- CVE-2019-1910439Monitor
ABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access Control
CriticalCVSS 9.8No exploitEPSS 1%abb · tg\/s3.2 firmwareApr 22, 2020
- CVE-2023-063639Monitor
Remote Code Execution via Command Injection
CriticalCVSS 9.8No exploitEPSS 1%abb · aspect-ent-2 firmwareJun 5, 2023
- CVE-2020-2467539Monitor
Weak Authentication in Symphony Plus
CriticalCVSS 9.8No exploitEPSS 1%abb · symphony \+ historianDec 22, 2020
- CVE-2020-2467339Monitor
SQL Injection in Symphony Plus
CriticalCVSS 9.8No exploitEPSS 1%abb · symphony \+ historianDec 22, 2020
- CVE-2022-094739Monitor
Arctic Wireless Gateway Firewall vulnerability
CriticalCVSS 9.8No exploitEPSS 1%abb · arg600a1220na firmwareMay 10, 2022
- CVE-2022-412639Monitor
Use of Default Password
CriticalCVSS 9.8No exploitEPSS 1%abb · rccmdMar 27, 2023