Skip to content
Noroxi

ABB records

162 published records for vendor abb.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

162 records
  • The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request.

    HighCVSS 8.8No exploitEPSS 52%

    abb · pb610 panel builder 600 firmwareJun 24, 2019

  • ABB Flow Computer and Remote Controllers Path Traversal Vulnerability in Totalflow TCP protocol can lead to root access

    CriticalCVSS 9.8No exploitEPSS 16%

    abb · rmc-100 firmwareJul 21, 2022

  • remote code execution

    CriticalCVSS 9.4Proof of conceptEPSS 19%

    abb · aspect-ent-12 firmwareJul 5, 2024

  • unauthorized file access

    CriticalCVSS 9.4Proof of conceptEPSS 17%

    abb · aspect-ent-12 firmwareJul 5, 2024

  • Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Mod

    CriticalCVSS 10.0No exploitEPSS 8%

    abb · interlink moduleMar 9, 2012

  • Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitr

    CriticalCVSS 10.0No exploitEPSS 8%

    abb · pcu400Sep 29, 2008

  • Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrativ

    CriticalCVSS 9.8No exploitEPSS 3%

    abb · gate-e1 firmwareJan 3, 2019

  • In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker

    CriticalCVSS 9.8No exploitEPSS 3%

    abb · srea-50 firmwareMay 24, 2018

  • In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acce

    CriticalCVSS 9.8No exploitEPSS 3%

    abb · ip gateway firmwareJun 6, 2018

  • ABB Central Licensing System - XML External Entity Injection

    CriticalCVSS 9.8No exploitEPSS 2%

    abb · 800xa systemApr 28, 2020

  • Denial of Service attack on Symphony Plus

    CriticalCVSS 9.8No exploitEPSS 2%

    abb · symphony \+ historianDec 22, 2020

  • ABB Central Licensing System - Information disclosure

    CriticalCVSS 9.8No exploitEPSS 2%

    abb · 800xa systemApr 28, 2020

  • In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication b

    CriticalCVSS 9.8No exploitEPSS 2%

    abb · plant connectNov 25, 2019

  • Service Control vulnerabilities allow access to service restart requests and vm configuration settings.

    HighCVSS 8.8No exploitEPSS 13%

    abb · aspect-ent-12 firmwareDec 5, 2024

  • CVE-2017-7933
    39Monitor

    In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unaut

    CriticalCVSS 9.8No exploitEPSS 2%

    abb · ip gateway firmwareJun 6, 2018

  • Authentication Bypass in Symphony Plus

    CriticalCVSS 9.8No exploitEPSS 1%

    abb · symphony \+ historianDec 22, 2020

  • OmniCore RobotWare Missing Authentication Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    abb · omnicore c30 firmwareDec 13, 2021

  • RVD#3327: No authentication required for accesing ABB IRC5 FTP server

    CriticalCVSS 9.8No exploitEPSS 1%

    abb · robotwareJul 15, 2020

  • RVD#3326: Hardcoded default credentials on IRC 5 OPC Server

    CriticalCVSS 9.8No exploitEPSS 1%

    abb · irb140 firmwareJul 15, 2020

  • ABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access Control

    CriticalCVSS 9.8No exploitEPSS 1%

    abb · tg\/s3.2 firmwareApr 22, 2020

  • CVE-2023-0636
    39Monitor

    Remote Code Execution via Command Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    abb · aspect-ent-2 firmwareJun 5, 2023

  • Weak Authentication in Symphony Plus

    CriticalCVSS 9.8No exploitEPSS 1%

    abb · symphony \+ historianDec 22, 2020

  • SQL Injection in Symphony Plus

    CriticalCVSS 9.8No exploitEPSS 1%

    abb · symphony \+ historianDec 22, 2020

  • CVE-2022-0947
    39Monitor

    Arctic Wireless Gateway Firewall vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    abb · arg600a1220na firmwareMay 10, 2022

  • CVE-2022-4126
    39Monitor

    Use of Default Password

    CriticalCVSS 9.8No exploitEPSS 1%

    abb · rccmdMar 27, 2023