Vulnerabilities > ABB > High

DATE CVE VULNERABILITY TITLE RISK
2023-05-17 CVE-2023-0863 Improper Authentication vulnerability in ABB products
Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC wallbox (JP).This issue affects Terra AC wallbox (UL40/80A): from 1.0;0 through 1.5.5; Terra AC wallbox (UL32A) : from 1.0;0 through 1.6.5; Terra AC wallbox (CE) (Terra AC MID): from 1.0;0 through 1.6.5; Terra AC wallbox (CE) Terra AC Juno CE: from 1.0;0 through 1.6.5; Terra AC wallbox (CE) Terra AC PTB : from 1.0;0 through 1.5.25; Terra AC wallbox (CE) Symbiosis: from 1.0;0 through 1.2.7; Terra AC wallbox (JP): from 1.0;0 through 1.6.5.
low complexity
abb CWE-287
8.8
2023-03-02 CVE-2023-0228 Improper Authentication vulnerability in ABB Symphony Plus S+ Operations 2.1/2.2/3.3
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.
low complexity
abb CWE-287
8.8
2023-02-24 CVE-2022-1607 Cross-Site Request Forgery (CSRF) vulnerability in ABB Infinity DC Power Plant and Ne843 S
Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415.
network
low complexity
abb CWE-352
8.8
2022-08-24 CVE-2022-34836 Path Traversal vulnerability in ABB Zenon
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries.
network
low complexity
abb CWE-22
8.2
2022-08-24 CVE-2022-34838 Insufficiently Protected Credentials vulnerability in ABB Zenon
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes.
local
low complexity
abb CWE-522
8.4
2022-06-15 CVE-2022-26057 Improper Privilege Management vulnerability in ABB Mint Workbench 5866
Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist.
local
low complexity
abb CWE-269
7.8
2022-06-15 CVE-2022-31216 Link Following vulnerability in ABB Automation Builder, Drive Composer and Mint Workbench
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist.
local
low complexity
abb CWE-59
7.8
2022-06-15 CVE-2022-31217 Link Following vulnerability in ABB Automation Builder, Drive Composer and Mint Workbench
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist.
local
low complexity
abb CWE-59
7.8
2022-06-15 CVE-2022-31218 Link Following vulnerability in ABB Automation Builder, Drive Composer and Mint Workbench
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist.
local
low complexity
abb CWE-59
7.8
2022-06-15 CVE-2022-31219 Link Following vulnerability in ABB Automation Builder, Drive Composer and Mint Workbench
Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist.
local
low complexity
abb CWE-59
7.8