← Back

Hitachienergy

hitachienergy

100 CVEs • 68 products

Products (68)

Click to collapse
Toggle
Esoms
esoms
Foxman Un
foxman-un
Unem
unem
Sdm600
sdm600
Asset Suite
asset_suite
Ellipse
ellipse
Pcm600
pcm600
650connectivitypackage
670connectivitypackage
Fox515t
fox515t
Sys600
sys600
Relion 630
relion_630
Relion 650
relion_650
Relion 670
relion_670
Rtu500
rtu500
Reb500
reb500
Fox615 Tego1
fox615_tego1
Gms600
gms600
Pwc600
pwc600
Fox615
fox615
Xcm20
xcm20
Rtu520
rtu520
Rtu530
rtu530
Rtu540
rtu540
Rtu560
rtu560
Tro610
tro610
Tro620
tro620
Tro670
tro670

CVEs (100)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an attacker to attack such as stored cross-site scripting by storing malicious content in the database.
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
7.6 HIGH· v3
6.5 MEDIUM· v2
Lack of input checks for SQL queries in ABB eSOMS versions 3.9 to 6.0.3 might allow an attacker SQL injection attacks against the backend database.
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
eSOMS versions 4.0 to 6.0.3 do not enforce password complexity settings, potentially resulting in lower access security due to insecure user passwords.
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
ABB eSOMS versions 4.0 to 6.0.3 use ASP.NET Viewstate without Message Authentication Code (MAC). Alterations to Viewstate might thus not be noticed.
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
For ABB eSOMS versions 4.0 to 6.0.3, HTTPS responses contain comments with sensitive information about the application. An attacker might use this detail information to specifically craft the attack.
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
3.5 LOW· v3
3.5 LOW· v2
For ABB eSOMS versions 4.0 to 6.0.2, the Secure Flag is not set in the HTTP response header. Unencrypted connections might access the cookie information, thus making it susceptible to eavesdropping.
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared....Show more
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
For ABB eSOMS versions 4.0 to 6.0.2, the HTTPOnly flag is not set. This can allow Javascript to access the cookie contents, which in turn might enable Cross Site Scripting.
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cr...Show more
For ABB eSOMS versions 4.0 to 6.0.2, the X-XSS-Protection HTTP response header is not set in responses from the web server. For older web browser not supporting Content Security Policy, this might increase the risk of Cross Site Scripting.Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious we...Show more
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP response. This can potentially allow 'ClickJacking' attacks where an attacker can frame parts of the application on a malicious web site, revealing sensitive user information such as authentication credentials.Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the application response. This can potentially allow browsers and proxies to cache sensitive information.
1Hitachienergy
1Asset Suite
Jun 17, 2026
Feb 17, 2020
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge...Show more
Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior to 9.5.3.2 and 9.6.0 enables full access to directly referenced objects. An attacker with knowledge of a resource's URL can access the resource directly.Show less
1Hitachienergy
1Relion 670 Firmware
Jun 17, 2026
Nov 27, 2019
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory.
1Hitachienergy
2Relion 650 Firmware
Relion 670 Firmware
Jun 17, 2026
Nov 27, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of servi...Show more
An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 series (versions 1.2.3.18, 2.0.0.11, 2.1.0.1 and prior) to reboot, which could cause a denial of service.Show less
1Hitachienergy
1Relion 630 Firmware
Nov 21, 2024
Jan 16, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
ABB Relion 630 devices 1.1 before 1.1.0.C0, 1.2 before 1.2.0.B3, and 1.3 before 1.3.0.A6 allow remote attackers to cause a denial of service (reboot) via a reboot command in an SPA message.
1Hitachienergy
1Esoms
Nov 21, 2024
Aug 29, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required t...Show more
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vulnerability.Show less
1Hitachienergy
1Sys600 Firmware
Nov 21, 2024
Feb 21, 2018
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target sys...Show more
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the access controls for the installed product files. The installation procedure leaves critical files open to manipulation by any authenticated user. An attacker can leverage this vulnerability to escalate privileges to SYSTEM. Was ZDI-CAN-5097.Show less
1Hitachienergy
1Ellipse
May 13, 2026
Dec 20, 2017
N/A· v4
8.8 HIGH· v3
2.9 LOW· v2
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to L...Show more
An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to LDAP/AD using the LDAP protocol. An attacker could exploit the vulnerability by sniffing local network traffic, allowing the discovery of authentication credentials.Show less
1Hitachienergy
1Fox515t Firmware
May 13, 2026
Nov 6, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identified, allowing a local attacker to provide a malicious parameter to the script that...Show more
An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identified, allowing a local attacker to provide a malicious parameter to the script that is not validated by the application, This could enable the attacker to retrieve any file on the server.Show less
1Hitachienergy
1Fox515t Firmware
May 13, 2026
Oct 18, 2017
N/A· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
The embedded web server on ABB Fox515T 1.0 devices is vulnerable to Local File Inclusion. It accepts a parameter that specifies a file for display or for use as a template. The filename is not validated; an attacker coul...Show more
The embedded web server on ABB Fox515T 1.0 devices is vulnerable to Local File Inclusion. It accepts a parameter that specifies a file for display or for use as a template. The filename is not validated; an attacker could retrieve any file.Show less