ABB kayıtları
abb üreticisine ait 162 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %3,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls11
- CWE-20 Improper Input Validation10
- CWE-287 Improper Authentication9
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor6
- CWE-732 Incorrect Permission Assignment for Critical Resource6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
162 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2019-7232İstismar yok | The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request.abb · pb610 panel builder 600 firmware · CWE-787 | Yüksek8,8 | — | %52,1 | 24 Haz 2019 |
44Planlayın | CVE-2022-0902İstismar yok | ABB Flow Computer and Remote Controllers Path Traversal Vulnerability in Totalflow TCP protocol can lead to root accessabb · rmc-100 firmware · CWE-22 | Kritik9,8 | — | %16,5 | 21 Tem 2022 |
43Planlayın | CVE-2024-6298Kavram kanıtı | remote code executionabb · aspect-ent-12 firmware · CWE-1287 | Kritik9,4 | — | %19,0 | 5 Tem 2024 |
42Planlayın | CVE-2024-6209Kavram kanıtı | unauthorized file accessabb · aspect-ent-12 firmware · CWE-552 | Kritik9,4 | — | %17,2 | 5 Tem 2024 |
42Planlayın | CVE-2012-0245İstismar yok | Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Modabb · interlink module · CWE-119 | Kritik10,0 | — | %8,2 | 9 Mar 2012 |
42Planlayın | CVE-2008-2474İstismar yok | Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitrabb · pcu400 · CWE-119 | Kritik10,0 | — | %7,9 | 29 Eyl 2008 |
40Planlayın | CVE-2018-18995İstismar yok | Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrativabb · gate-e1 firmware · CWE-306 | Kritik9,8 | — | %2,6 | 3 Oca 2019 |
40Planlayın | CVE-2017-9664İstismar yok | In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker abb · srea-50 firmware · CWE-23 | Kritik9,8 | — | %2,6 | 24 May 2018 |
40Planlayın | CVE-2017-7931İstismar yok | In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acceabb · ip gateway firmware · CWE-287 | Kritik9,8 | — | %2,5 | 6 Haz 2018 |
40Planlayın | CVE-2020-8479İstismar yok | ABB Central Licensing System - XML External Entity Injectionabb · 800xa system · CWE-91 | Kritik9,8 | — | %2,3 | 28 Nis 2020 |
40Planlayın | CVE-2020-24679İstismar yok | Denial of Service attack on Symphony Plusabb · symphony \+ historian · CWE-20 | Kritik9,8 | — | %1,9 | 22 Ara 2020 |
40Planlayın | CVE-2020-8481İstismar yok | ABB Central Licensing System - Information disclosureabb · 800xa system · CWE-200 | Kritik9,8 | — | %1,9 | 28 Nis 2020 |
40Planlayın | CVE-2019-18250İstismar yok | In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication babb · plant connect · CWE-288 | Kritik9,8 | — | %1,7 | 25 Kas 2019 |
39İzleyin | CVE-2024-51544İstismar yok | Service Control vulnerabilities allow access to service restart requests and vm configuration settings.abb · aspect-ent-12 firmware · CWE-15 | Yüksek8,8 | — | %13,2 | 5 Ara 2024 |
39İzleyin | CVE-2017-7933İstismar yok | In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unautabb · ip gateway firmware · CWE-522 | Kritik9,8 | — | %1,7 | 6 Haz 2018 |
39İzleyin | CVE-2020-24683İstismar yok | Authentication Bypass in Symphony Plusabb · symphony \+ historian · CWE-305 | Kritik9,8 | — | %1,5 | 22 Ara 2020 |
39İzleyin | CVE-2021-22279İstismar yok | OmniCore RobotWare Missing Authentication Vulnerabilityabb · omnicore c30 firmware · CWE-306 | Kritik9,8 | — | %1,4 | 13 Ara 2021 |
39İzleyin | CVE-2020-10288İstismar yok | RVD#3327: No authentication required for accesing ABB IRC5 FTP serverabb · robotware · CWE-284 | Kritik9,8 | — | %1,4 | 15 Tem 2020 |
39İzleyin | CVE-2020-10287İstismar yok | RVD#3326: Hardcoded default credentials on IRC 5 OPC Serverabb · irb140 firmware · CWE-255 | Kritik9,8 | — | %1,4 | 15 Tem 2020 |
39İzleyin | CVE-2019-19104İstismar yok | ABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access Controlabb · tg\/s3.2 firmware · CWE-287 | Kritik9,8 | — | %1,4 | 22 Nis 2020 |
39İzleyin | CVE-2023-0636İstismar yok | Remote Code Execution via Command Injectionabb · aspect-ent-2 firmware · CWE-77 | Kritik9,8 | — | %1,4 | 5 Haz 2023 |
39İzleyin | CVE-2020-24675İstismar yok | Weak Authentication in Symphony Plusabb · symphony \+ historian · CWE-287 | Kritik9,8 | — | %1,2 | 22 Ara 2020 |
39İzleyin | CVE-2020-24673İstismar yok | SQL Injection in Symphony Plusabb · symphony \+ historian · CWE-89 | Kritik9,8 | — | %1,1 | 22 Ara 2020 |
39İzleyin | CVE-2022-0947İstismar yok | Arctic Wireless Gateway Firewall vulnerabilityabb · arg600a1220na firmware · CWE-665 | Kritik9,8 | — | %0,9 | 10 May 2022 |
39İzleyin | CVE-2022-4126İstismar yok | Use of Default Passwordabb · rccmd · CWE-1393 | Kritik9,8 | — | %0,6 | 27 Mar 2023 |
- CVE-2019-723251Planlayın
The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request.
YüksekCVSS 8,8İstismar yokEPSS %52abb · pb610 panel builder 600 firmware24 Haz 2019
- CVE-2022-090244Planlayın
ABB Flow Computer and Remote Controllers Path Traversal Vulnerability in Totalflow TCP protocol can lead to root access
KritikCVSS 9,8İstismar yokEPSS %16abb · rmc-100 firmware21 Tem 2022
- CVE-2024-629843Planlayın
remote code execution
KritikCVSS 9,4Kavram kanıtıEPSS %19abb · aspect-ent-12 firmware5 Tem 2024
- CVE-2024-620942Planlayın
unauthorized file access
KritikCVSS 9,4Kavram kanıtıEPSS %17abb · aspect-ent-12 firmware5 Tem 2024
- CVE-2012-024542Planlayın
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Mod
KritikCVSS 10,0İstismar yokEPSS %8abb · interlink module9 Mar 2012
- CVE-2008-247442Planlayın
Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attackers to execute arbitr
KritikCVSS 10,0İstismar yokEPSS %8abb · pcu40029 Eyl 2008
- CVE-2018-1899540Planlayın
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrativ
KritikCVSS 9,8İstismar yokEPSS %3abb · gate-e1 firmware3 Oca 2019
- CVE-2017-966440Planlayın
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker
KritikCVSS 9,8İstismar yokEPSS %3abb · srea-50 firmware24 May 2018
- CVE-2017-793140Planlayın
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to acce
KritikCVSS 9,8İstismar yokEPSS %3abb · ip gateway firmware6 Haz 2018
- CVE-2020-847940Planlayın
ABB Central Licensing System - XML External Entity Injection
KritikCVSS 9,8İstismar yokEPSS %2abb · 800xa system28 Nis 2020
- CVE-2020-2467940Planlayın
Denial of Service attack on Symphony Plus
KritikCVSS 9,8İstismar yokEPSS %2abb · symphony \+ historian22 Ara 2020
- CVE-2020-848140Planlayın
ABB Central Licensing System - Information disclosure
KritikCVSS 9,8İstismar yokEPSS %2abb · 800xa system28 Nis 2020
- CVE-2019-1825040Planlayın
In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication b
KritikCVSS 9,8İstismar yokEPSS %2abb · plant connect25 Kas 2019
- CVE-2024-5154439İzleyin
Service Control vulnerabilities allow access to service restart requests and vm configuration settings.
YüksekCVSS 8,8İstismar yokEPSS %13abb · aspect-ent-12 firmware5 Ara 2024
- CVE-2017-793339İzleyin
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unaut
KritikCVSS 9,8İstismar yokEPSS %2abb · ip gateway firmware6 Haz 2018
- CVE-2020-2468339İzleyin
Authentication Bypass in Symphony Plus
KritikCVSS 9,8İstismar yokEPSS %1abb · symphony \+ historian22 Ara 2020
- CVE-2021-2227939İzleyin
OmniCore RobotWare Missing Authentication Vulnerability
KritikCVSS 9,8İstismar yokEPSS %1abb · omnicore c30 firmware13 Ara 2021
- CVE-2020-1028839İzleyin
RVD#3327: No authentication required for accesing ABB IRC5 FTP server
KritikCVSS 9,8İstismar yokEPSS %1abb · robotware15 Tem 2020
- CVE-2020-1028739İzleyin
RVD#3326: Hardcoded default credentials on IRC 5 OPC Server
KritikCVSS 9,8İstismar yokEPSS %1abb · irb140 firmware15 Tem 2020
- CVE-2019-1910439İzleyin
ABB/Busch-Jaeger Telephone Gateway TG/S 3.2 Improper Authentication and Access Control
KritikCVSS 9,8İstismar yokEPSS %1abb · tg\/s3.2 firmware22 Nis 2020
- CVE-2023-063639İzleyin
Remote Code Execution via Command Injection
KritikCVSS 9,8İstismar yokEPSS %1abb · aspect-ent-2 firmware5 Haz 2023
- CVE-2020-2467539İzleyin
Weak Authentication in Symphony Plus
KritikCVSS 9,8İstismar yokEPSS %1abb · symphony \+ historian22 Ara 2020
- CVE-2020-2467339İzleyin
SQL Injection in Symphony Plus
KritikCVSS 9,8İstismar yokEPSS %1abb · symphony \+ historian22 Ara 2020
- CVE-2022-094739İzleyin
Arctic Wireless Gateway Firewall vulnerability
KritikCVSS 9,8İstismar yokEPSS %1abb · arg600a1220na firmware10 May 2022
- CVE-2022-412639İzleyin
Use of Default Password
KritikCVSS 9,8İstismar yokEPSS %1abb · rccmd27 Mar 2023