Vulnerabilities > ABB > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-08-24 CVE-2022-34837 Insufficiently Protected Credentials vulnerability in ABB Zenon
Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon.
local
low complexity
abb CWE-522
6.1
2022-06-21 CVE-2022-1596 Incorrect Permission Assignment for Critical Resource vulnerability in ABB products
Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node.
network
low complexity
abb CWE-732
6.5
2022-06-02 CVE-2022-28702 Incorrect Default Permissions vulnerability in ABB E-Design
Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine.
local
low complexity
abb CWE-276
5.5
2021-10-28 CVE-2021-22278 Improper Certificate Validation vulnerability in ABB Update Manager
A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.
local
low complexity
abb CWE-295
6.7
2021-09-23 CVE-2021-22276 Improper Validation of Integrity Check Value vulnerability in ABB products
The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to the free@home System Access Point.
local
low complexity
abb CWE-354
5.5
2020-05-29 CVE-2020-8482 Insecure Storage of Sensitive Information vulnerability in ABB Device Library Wizard 6.0.3.2/6.1.0
Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data
local
low complexity
abb CWE-922
5.5
2020-04-27 CVE-2020-11420 Path Traversal vulnerability in multiple products
UPS Adapter CS141 before 1.90 allows Directory Traversal.
network
low complexity
abb generex CWE-22
6.5
2020-04-22 CVE-2019-19107 Cleartext Transmission of Sensitive Information vulnerability in multiple products
The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and services transfer the password in plaintext (although hidden when displayed).
local
low complexity
abb busch-jaeger CWE-319
5.5
2020-04-22 CVE-2019-19105 Insufficiently Protected Credentials vulnerability in multiple products
The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current settings and configuration of the application, including credentials of existing user accounts and other configuration's credentials in plaintext.
local
low complexity
abb busch-jaeger CWE-522
5.5
2019-12-18 CVE-2019-18995 Improper Input Validation vulnerability in ABB Pb610 Panel Builder 600 1.90.0.975/2.8.0.424
The HMISimulator component of ABB PB610 Panel Builder 600 versions 2.8.0.424 and earlier fails to validate the content-length field for HTTP requests, exposing HMISimulator to denial of service via crafted HTTP requests manipulating the content-length setting.
network
low complexity
abb CWE-20
5.3