Abb
abb
161 CVEs • 391 products
Products (391)
Click to collapseToggle
Products (391)
Click to collapse
CVEs (161)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Abb Busch Jaeger26186/11 Firmware Tg/s3.2 FirmwareJun 17, 2026 Apr 22, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows an unauthorized user to access data marked as restricted, such as viewing or editing user profil...Show more |
2Abb Busch Jaeger26186/11 Firmware Tg/s3.2 FirmwareJun 17, 2026 Apr 22, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credentials of existing user accounts and other co...Show more |
2Abb Busch Jaeger26186/11 Firmware Tg/s3.2 FirmwareJun 17, 2026 Apr 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different endpoints of the application without authenticating by accessing a specific uniform resource locator (U...Show more |
1Abb 8Cp651 Web Firmware Cp651 FirmwareCp661 Web Firmware+5 moreJun 17, 2026 Jan 14, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. |
The HMISimulator component of ABB PB610 Panel Builder 600 uses the readFile/writeFile interface to manipulate the work file. Path configuration in PB610 HMISimulator versions 2.8.0.424 and earlier potentially allows acce...Show more |
Path settings in HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier accept DLLs outside of the program directory, potentially allowing an attacker with access to the local file system the e...Show more |
1Abb 1Pb610 Panel Builder 600 Jun 17, 2026 Dec 18, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests...Show more |
Due to a lack of file length check, the HMIStudio component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier crashes when trying to load an empty *.JPR application file. An attacker with access to the file s...Show more |
1Abb 2Plant Connect Power Generation Information ManagerJun 17, 2026 Nov 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable to authentication bypass, which may allow an attacker to remotely bypass authentication and extract...Show more |
1Abb 16Cp620 Web Firmware Cp620 FirmwareCp630 Web Firmware+13 moreJun 17, 2026 Jun 27, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI interface. These credentials allow the provisioning tool "Panel Builder 600" to flash a new interface...Show more |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 27, 2019 N/A· v4 7.3 HIGH· v3 4.1 MEDIUM· v2 In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP server functionality to download and upload files. An unauthenticated attac...Show more |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 27, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication and gain access to privileged functions. Specifically, /cgi/loginDefaultUser creates a session in an...Show more |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 27, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%0...Show more |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 24, 2019 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 The ABB IDAL FTP server is vulnerable to a buffer overflow when a long string is sent by an authenticated attacker. This overflow is handled, but terminates the process. An authenticated attacker can send a FTP command s...Show more |
1Abb 8Board Support Package Un31 Cp620 Web FirmwareCp620 Firmware+5 moreJun 17, 2026 Jun 24, 2019 N/A· v4 8.3 HIGH· v3 5.4 MEDIUM· v2 The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 o...Show more |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 24, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value overflows a buffer and overwrites a Structured Exception Handler (SEH) address. An unaut...Show more |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 24, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory...Show more |
5Abb PhoenixcontactSchneider Electric+2 more106ed1052 1cc01 0ba8 Firmware 6es7211 1ae40 0xb0 Firmware6es7314 6eh04 0ab0 Firmware+7 moreJun 17, 2026 Apr 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers have found some controllers are susceptible to a denial-of-service attack due to a flood of network...Show more |
The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser of the Text Editor wherein the application doesn't properly prevent the insertion of specially crafte...Show more |
The product CMS-770 (Software Versions 1.7.1 and prior)is vulnerable that an attacker can read sensitive configuration files by bypassing the user authentication mechanism. |