← Back

Abb

abb

161 CVEs • 391 products

Products (391)

Click to collapse
Toggle
Zenon
zenon
800xa System
800xa_system
Pcm600
pcm600
Base Software
base_software
Compact Hmi
compact_hmi
T Mac Plus
t-mac_plus
800xa
Robotware
robotware
Robotstudio
robotstudio
Webware Sdk
webware_sdk
Mms Server
mms_server
Opc Server
opc_server
E Design
e-design
Advabuild
advabuild
Pcu400
pcu400
Pc Sdk
pc_sdk
Pickmaster 3
pickmaster_3
Pickmaster 5
pickmaster_5
Robview 5
robview_5
Quickteach
quickteach
Robotstudio S4
robotstudio_s4
S4 Opc Server
s4_opc_server

CVEs (161)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Abb
2Eth Fw Firmware
Fw Firmware
Nov 21, 2024
Jan 31, 2019
N/A· v4
4.3 MEDIUM· v3
3.3 LOW· v2
The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicious language file by bypassing the user authentication mechanism.
1Abb
2Gate E1 Firmware
Gate E2 Firmware
Nov 21, 2024
Jan 3, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker using the administrative web interface to insert an HTML/Javascript payload into any of the device prop...Show more
Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker using the administrative web interface to insert an HTML/Javascript payload into any of the device properties, which may allow an attacker to display/execute the payload in a visitor browser.Show less
1Abb
2Gate E1 Firmware
Gate E2 Firmware
Nov 21, 2024
Jan 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, includin...Show more
Pluto Safety PLC Gateway Ethernet devices ABB GATE-E1 and GATE-E2 all versions do not allow authentication to be configured on administrative telnet or web interfaces, which could enable various effects vectors, including conducting device resets, reading or modifying registers, and changing configuration settings such as IP addresses.Show less
1Abb
1Panel Builder 800
Nov 21, 2024
Jul 18, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
ABB Panel Builder 800 all versions has an improper input validation vulnerability which may allow an attacker to insert and run arbitrary code on a computer where the affected product is used.
1Abb
1Ip Gateway Firmware
Nov 21, 2024
Jun 6, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text, which may allow an attacker to gain unauthorized access.
1Abb
1Ip Gateway Firmware
Nov 21, 2024
Jun 6, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the configuration files and application pages without authentication.
1Abb
1Ip Gateway Firmware
Nov 21, 2024
Jun 6, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.
1Abb
2Srea 01 Firmware
Srea 50 Firmware
Nov 21, 2024
May 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker may access internal files of ABB SREA-01 and SREA-50 legacy remote monitoring to...Show more
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker may access internal files of ABB SREA-01 and SREA-50 legacy remote monitoring tools without any authorization over the network using a HTTP request which refers to files using ../../ relative paths. Once the internal password file is retrieved, the password hash can be identified using a brute force attack. There is also an exploit allowing running of commands after authorization.Show less
1Abb
1Netcadops
Jun 17, 2026
Feb 20, 2018
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior, netCADOPS Web Application Version 7.2x and prior, netCADOPS Web Applic...Show more
An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior, netCADOPS Web Application Version 7.2x and prior, netCADOPS Web Application Version 8.0 and prior, and netCADOPS Web Application Version 8.1 and prior. A vulnerability exists in the password entry section of netCADOPS Web Application that may expose critical database information.Show less
1Abb
2Vsn300 Firmware
Vsn300 For React Firmware
May 13, 2026
Aug 7, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (...Show more
An Improper Authentication issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access internal information about status and connected devices without authenticating.Show less
1Abb
2Vsn300 Firmware
Vsn300 For React Firmware
May 13, 2026
Aug 7, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not p...Show more
A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger Card for React versions 2.1.3 and prior. The web application does not properly restrict privileges of the Guest account. A malicious user may be able to gain access to configuration information that should be restricted.Show less
1Abb
1Pcm600
May 6, 2026
Jun 10, 2016
N/A· v4
3.3 LOW· v3
1.9 LOW· v2
ABB PCM600 before 2.7 improperly stores PCM600 authentication credentials, which allows local users to obtain sensitive information via unspecified vectors.
1Abb
1Pcm600
May 6, 2026
Jun 10, 2016
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.
1Abb
1Pcm600
May 6, 2026
Jun 10, 2016
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.
1Abb
1Pcm600
May 6, 2026
Jun 10, 2016
N/A· v4
2.8 LOW· v3
1.9 LOW· v2
ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leveraging read access to the ACTConfig configur...Show more
ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leveraging read access to the ACTConfig configuration file.Show less
1Abb
1Panel Builder 800
May 6, 2026
Mar 18, 2016
N/A· v4
7.2 HIGH· v3
6.0 MEDIUM· v2
Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
1Abb
2Robotstudio
Test Signal Viewer
May 6, 2026
Nov 7, 2014
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Untrusted search path vulnerability in ABB RobotStudio 5.6x before 5.61.02 and Test Signal Viewer 1.5 allows local users to gain privileges via a Trojan horse DLL that is accessed as a result of incorrect DLL configurati...Show more
Untrusted search path vulnerability in ABB RobotStudio 5.6x before 5.61.02 and Test Signal Viewer 1.5 allows local users to gain privileges via a Trojan horse DLL that is accessed as a result of incorrect DLL configuration by an optional installation program.Show less
2Abb
Ni
5Datamanager
LabviewLabwindows+2 more
Apr 29, 2026
Aug 6, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlier, National Instruments LabVIEW 2012 SP1 and earlier, the Data Analysis...Show more
Multiple absolute path traversal vulnerabilities in National Instruments cwui.ocx, as used in National Instruments LabWindows/CVI 2012 SP1 and earlier, National Instruments LabVIEW 2012 SP1 and earlier, the Data Analysis component in ABB DataManager 1 through 6.3.6, and other products allow remote attackers to create and execute arbitrary files via a full pathname in an argument to the ExportStyle method in the (1) CWNumEdit, (2) CWGraph, (3) CWBoolean, (4) CWSlide, or (5) CWKnob ActiveX control, in conjunction with file content in the (a) Caption or (b) FormatString property value.Show less
1Abb
7Interlink Module
QuickteachRobotstudio Lite+4 more
Apr 29, 2026
Apr 18, 2012
N/A· v4
N/A· v3
7.7 HIGH· v2
Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, WebWare SDK, Interlink Module, S4 OPC Server, QuickTeach, RobotStudio S4, and RobotStudio Lite allow remote attackers to ex...Show more
Multiple stack-based buffer overflows in (1) COM and (2) ActiveX controls in ABB WebWare Server, WebWare SDK, Interlink Module, S4 OPC Server, QuickTeach, RobotStudio S4, and RobotStudio Lite allow remote attackers to execute arbitrary code via crafted input data.Show less
1Abb
10Interlink Module
Irc5 Opc ServerPc Sdk+7 more
Apr 29, 2026
Mar 9, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWar...Show more
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWare SDK, and WebWare Server, allow remote attackers to execute arbitrary code via a crafted (1) 0xA or (2) 0xE Netscan packet.Show less