<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_abb/10</id>
  <title>Most recent entries from csaf_abb</title>
  <updated>2026-10-02T23:36:34.980514+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/3adr011377</id>
    <title>3ADR011377 — AC500 V3 Multiple vulnerabilities</title>
    <updated>2025-01-07T00:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An update is available that resolves a publicly reported vulnerability in the product versions listed as affected in the advisory. 
An attacker who successfully exploited these vulnerabilities could call shell functions (CVE-2023-6357), 
crash the PLC (CVE-2024-5000), crash the web server of the PLC (CVE-2024-8175), grant read access to 
files (CVE-2024-12429) or enable command execution (CVE-2024-12430).
The vulnerabilities CVE-2023-6357, CVE-2024-12429 and CVE-2024-12430 require successful authentication.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/3adr011377"/>
    <published>2025-01-07T00:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/9akk108470a5466</id>
    <title>9AKK108470A5466 — Drive Composer Path Traversal Vulnerability</title>
    <updated>2025-01-10T00:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An update is available that resolves vulnerability in the product versions as affected in this advisory.
An attacker who successfully exploits the vulnerability could get unauthorized access to the file system
on the host machine. This can lead to the execution of arbitrary code, data leakage, or even complete
system compromise.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/9akk108470a5466"/>
    <published>2025-02-05T00:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/9akk108470a6775</id>
    <title>9AKK108470A6775 — Hardcoded credentials in ASPECT Energy Management System</title>
    <updated>2025-02-06T00:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB became aware of vulnerabilities in the product versions listed as affected in the advisory. ASPECT devices are not intended to be internet-facing. A product advisory issued in June 2023 informed customers of this already.
An attacker who successfully exploits these vulnerabilities could gain unauthorized access and potentially compromise the system's - and log-file -  confidentiality, integrity and availability. 
ABB requires, as noted in previous security advisories and user documentation, that ASPECT should not be exposed to the internet or any other insecure network.
Note: In order to exploit an ASPECT, an attacker would need a misconfigured system.
ABB strongly advises customers and system integrators to follow the instructions documented in: FBXi, CBXi and ASPECT® SOLUTIONS, which can be downloaded from the ABB library.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/9akk108470a6775"/>
    <published>2025-02-05T00:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/7paa012159</id>
    <title>7PAA012159 — System 800xA 5.1.x, 6.0.3.x, 6.1.1.x, 6.2.x - VideONet Camera passwords stored in clear text</title>
    <updated>2025-02-10T00:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of a vulnerability related to the VideONet product. The vulnerability is applicable in the System 800xA versions listed as affected in the advisory, where the VideONet product is used. There will be no update/resolution of this vulnerability in System 800xA. Instead, the strategy for ABB is to offer existing customers using VideONet a transfer to a new product, Camera Connect. This will be offered as soon as Camera Connect is available as a product.
An attacker who successfully exploited the vulnerability could, in the worst-case scenario, stop or manipulate the video feed.
There is no impact to other Operator station functions (graphics, trends, faceplates, etc.) and Control operations are not impacted at all.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/7paa012159"/>
    <published>2025-02-10T00:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/9akk108470a5684</id>
    <title>9AKK108470A5684 — FLXeon Controllers Cyber Security Advisory</title>
    <updated>2025-02-14T00:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>An update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.</p>
<p>FLXEON devices are not intended to be internet-facing. A product advisory issued in June 2023 informed customers of this parameter.</p>
<p>An attacker can successfully exploit these vulnerabilities and could take remote control of the product and potentially insert and run arbitrary code. 
ABB requires, as noted in previous security advisories and user documentation, that FLXEON should not be exposed to the internet or any other insecure network.
Note: In order to exploit an FLXEON, an attacker would need a misconfigured system.</p>
<p>ABB strongly advises customers and system integrators to follow the instructions documented in: FBXi, CBXi and ASPECT® SOLUTIONS, which can be downloaded from the ABB library (See in the reference section).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/9akk108470a5684"/>
    <published>2025-01-20T00:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/9akk108470a8565</id>
    <title>9AKK108470A8565 — RMC-100 Vulnerability in the Web UI (REST Interface)</title>
    <updated>2025-03-11T00:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An update is available that resolves a vulnerability in the product versions listed as affected in this advisory.
An attacker who successfully exploited this vulnerability could cause the web UI to stop.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/9akk108470a8565"/>
    <published>2025-03-11T00:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/9akk108470a9491</id>
    <title>9AKK108470A9491 — ABB ACS880 +N8010 Drives CODESYS RTS Vulnerabilities</title>
    <updated>2025-03-27T00:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Multiple vulnerabilities regarding the CODESYS Runtime System from CODESYS Group have been publicly reported. CODESYS Runtime System is utilized in the firmware of ABB ACS880 drives to provide IEC 61131-3 programming capabilities.</p>
<p>These vulnerabilities could lead to out-of-bound memory access. Successful exploit may result in a denial-of-service condition or arbitrary code execution. Firmware updates are available that mitigate the publicly reported vulnerabilities of the product versions listed as affected in this advisory.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/9akk108470a9491"/>
    <published>2025-03-26T00:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/9akk108470a9494</id>
    <title>9AKK108470A9494 — Low Voltage DC Drives and Power Controllers CODESYS RTS Vulnerabilities</title>
    <updated>2025-03-27T00:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CODESYS group published several vulnerabilities regarding the CODESYS Runtime System, which is included in the firmware of ABB LV DC drives and power controllers. It is used to implement a selection of features and to provide IEC 611131-3 programming capabilities.
These vulnerabilities include memory corruption issues that could lead to out-of-bound memory access. Subsequently, a successful exploit could allow attackers to trigger a denial-of-service condition or execute arbitrary code over the fieldbus interfaces.   Exploiting these vulnerabilities requires an IEC 61131-3 license being present on the memory unit of the drive or power controller.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/9akk108470a9494"/>
    <published>2025-03-26T00:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga002427</id>
    <title>2NGA002427 — ABB Arctic ARG600, ARC600, ARR600, ARP600 Arctic Wireless Gateway Modem Module and OpenSSH vulnerabilities</title>
    <updated>2025-04-07T10:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of the vulnerabilities in the product versions listed as affected in this advisory.
An attacker who successfully exploited modem module vulnerabilities could run arbitrary code in the wireless modem module of the product. This could lead to denial of service or tampering with unencrypted traffic.
An attacker who successfully exploited the OpenSSH vulnerability could run arbitrary code in the product with privileged user permissions. This could cause the product to stop, make the product inaccessible, or the attacker could take control of the product.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga002427"/>
    <published>2025-04-07T10:30:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga002579</id>
    <title>2NGA002579 — ABB Arctic communication solution ARM600 Vulnerabilities</title>
    <updated>2025-04-07T10:30:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>ABB is aware of public reports of a vulnerabilities in product versions listed as affected in this advisory. An attacker who successfully exploited these vulnerabilities could cause the product to stop, make the product inacces-sible, take remote control of the product or insert and run arbitrary code.
As part of ABB product lifecycle policy, once a product transitions to end-of-life, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document, such as using a private APN cellular network between Arctic wireless gateways and ARM600 for establishing VPN tunnels, to mitigate security risks and avoid potential vulnerabilities.
As part of ABB product lifecycle policy, once a product transitions to Limited state, we discontinue maintenance, security patches, and technical support to focus on current and future technologies. While the product will continue to function, we strongly recommend implementing mitigations defined in this document to mitigate security risks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga002579"/>
    <published>2025-04-07T10:30:00+00:00</published>
  </entry>
</feed>
