<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_abb</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 20:48:48 +0000</lastBuildDate>
    <item>
      <title>7PAA013309 — System 800xA SECURITY Advisory - ABB 800xA Base 6.0.x, 6.1.x CSLib communication DoS vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/7paa013309</link>
      <description>&lt;p&gt;ABB is aware of a vulnerability in the product versions listed as affected in the advisory.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited this vulnerability could cause services to crash and restart by sending specifically crafted messages.&lt;/p&gt;
&lt;p&gt;The vulnerability only affects 800xA services in PC based client/server nodes. Controllers are not affected by this vulnerability&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of a vulnerability in the product versions listed as affected in the advisory.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited this vulnerability could cause services to crash and restart by sending specifically crafted messages.&lt;/p&gt;
&lt;p&gt;The vulnerability only affects 800xA services in PC based client/server nodes. Controllers are not affected by this vulnerability&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/7paa013309</guid>
      <pubDate>Wed, 05 Jun 2024 00:30:00 +0000</pubDate>
    </item>
    <item>
      <title>3ADR011377 — AC500 V3 Multiple vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/3adr011377</link>
      <description>&lt;p&gt;An update is available that resolves a publicly reported vulnerability in the product versions listed as affected in the advisory. 
An attacker who successfully exploited these vulnerabilities could call shell functions (CVE-2023-6357), 
crash the PLC (CVE-2024-5000), crash the web server of the PLC (CVE-2024-8175), grant read access to 
files (CVE-2024-12429) or enable command execution (CVE-2024-12430).
The vulnerabilities CVE-2023-6357, CVE-2024-12429 and CVE-2024-12430 require successful authentication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An update is available that resolves a publicly reported vulnerability in the product versions listed as affected in the advisory. 
An attacker who successfully exploited these vulnerabilities could call shell functions (CVE-2023-6357), 
crash the PLC (CVE-2024-5000), crash the web server of the PLC (CVE-2024-8175), grant read access to 
files (CVE-2024-12429) or enable command execution (CVE-2024-12430).
The vulnerabilities CVE-2023-6357, CVE-2024-12429 and CVE-2024-12430 require successful authentication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/3adr011377</guid>
      <pubDate>Tue, 07 Jan 2025 00:30:00 +0000</pubDate>
    </item>
    <item>
      <title>SA25P001 — Automation Runtime and mapp View Use of insecure algorithm for self-signed certificates</title>
      <link>https://cve.radiocsirt.org/vuln/sa25p001</link>
      <description>&lt;p&gt;An update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited this vulnerability may masquerade as services on affected devices.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploited this vulnerability may masquerade as services on affected devices.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sa25p001</guid>
      <pubDate>Wed, 15 Jan 2025 00:30:00 +0000</pubDate>
    </item>
    <item>
      <title>9AKK108470A5684 — FLXeon Controllers Cyber Security Advisory</title>
      <link>https://cve.radiocsirt.org/vuln/9akk108470a5684</link>
      <description>&lt;p&gt;An update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.&lt;/p&gt;
&lt;p&gt;FLXEON devices are not intended to be internet-facing. A product advisory issued in June 2023 informed customers of this parameter.&lt;/p&gt;
&lt;p&gt;An attacker can successfully exploit these vulnerabilities and could take remote control of the product and potentially insert and run arbitrary code. 
ABB requires, as noted in previous security advisories and user documentation, that FLXEON should not be exposed to the internet or any other insecure network.
Note: In order to exploit an FLXEON, an attacker would need a misconfigured system.&lt;/p&gt;
&lt;p&gt;ABB strongly advises customers and system integrators to follow the instructions documented in: FBXi, CBXi and ASPECT® SOLUTIONS, which can be downloaded from the ABB library (See in the reference section).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.&lt;/p&gt;
&lt;p&gt;FLXEON devices are not intended to be internet-facing. A product advisory issued in June 2023 informed customers of this parameter.&lt;/p&gt;
&lt;p&gt;An attacker can successfully exploit these vulnerabilities and could take remote control of the product and potentially insert and run arbitrary code. 
ABB requires, as noted in previous security advisories and user documentation, that FLXEON should not be exposed to the internet or any other insecure network.
Note: In order to exploit an FLXEON, an attacker would need a misconfigured system.&lt;/p&gt;
&lt;p&gt;ABB strongly advises customers and system integrators to follow the instructions documented in: FBXi, CBXi and ASPECT® SOLUTIONS, which can be downloaded from the ABB library (See in the reference section).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/9akk108470a5684</guid>
      <pubDate>Mon, 20 Jan 2025 00:30:00 +0000</pubDate>
    </item>
    <item>
      <title>9AKK108470A5466 — Drive Composer Path Traversal Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/9akk108470a5466</link>
      <description>&lt;p&gt;An update is available that resolves vulnerability in the product versions as affected in this advisory.
An attacker who successfully exploits the vulnerability could get unauthorized access to the file system
on the host machine. This can lead to the execution of arbitrary code, data leakage, or even complete
system compromise.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An update is available that resolves vulnerability in the product versions as affected in this advisory.
An attacker who successfully exploits the vulnerability could get unauthorized access to the file system
on the host machine. This can lead to the execution of arbitrary code, data leakage, or even complete
system compromise.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/9akk108470a5466</guid>
      <pubDate>Wed, 05 Feb 2025 00:30:00 +0000</pubDate>
    </item>
    <item>
      <title>9AKK108470A6775 — Hardcoded credentials in ASPECT Energy Management System</title>
      <link>https://cve.radiocsirt.org/vuln/9akk108470a6775</link>
      <description>&lt;p&gt;ABB became aware of vulnerabilities in the product versions listed as affected in the advisory. ASPECT devices are not intended to be internet-facing. A product advisory issued in June 2023 informed customers of this already.
An attacker who successfully exploits these vulnerabilities could gain unauthorized access and potentially compromise the system&amp;#39;s - and log-file -  confidentiality, integrity and availability. 
ABB requires, as noted in previous security advisories and user documentation, that ASPECT should not be exposed to the internet or any other insecure network.
Note: In order to exploit an ASPECT, an attacker would need a misconfigured system.
ABB strongly advises customers and system integrators to follow the instructions documented in: FBXi, CBXi and ASPECT® SOLUTIONS, which can be downloaded from the ABB library.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB became aware of vulnerabilities in the product versions listed as affected in the advisory. ASPECT devices are not intended to be internet-facing. A product advisory issued in June 2023 informed customers of this already.
An attacker who successfully exploits these vulnerabilities could gain unauthorized access and potentially compromise the system&amp;#39;s - and log-file -  confidentiality, integrity and availability. 
ABB requires, as noted in previous security advisories and user documentation, that ASPECT should not be exposed to the internet or any other insecure network.
Note: In order to exploit an ASPECT, an attacker would need a misconfigured system.
ABB strongly advises customers and system integrators to follow the instructions documented in: FBXi, CBXi and ASPECT® SOLUTIONS, which can be downloaded from the ABB library.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/9akk108470a6775</guid>
      <pubDate>Wed, 05 Feb 2025 00:30:00 +0000</pubDate>
    </item>
    <item>
      <title>7PAA012159 — System 800xA 5.1.x, 6.0.3.x, 6.1.1.x, 6.2.x - VideONet Camera passwords stored in clear text</title>
      <link>https://cve.radiocsirt.org/vuln/7paa012159</link>
      <description>&lt;p&gt;ABB is aware of a vulnerability related to the VideONet product. The vulnerability is applicable in the System 800xA versions listed as affected in the advisory, where the VideONet product is used. There will be no update/resolution of this vulnerability in System 800xA. Instead, the strategy for ABB is to offer existing customers using VideONet a transfer to a new product, Camera Connect. This will be offered as soon as Camera Connect is available as a product.
An attacker who successfully exploited the vulnerability could, in the worst-case scenario, stop or manipulate the video feed.
There is no impact to other Operator station functions (graphics, trends, faceplates, etc.) and Control operations are not impacted at all.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of a vulnerability related to the VideONet product. The vulnerability is applicable in the System 800xA versions listed as affected in the advisory, where the VideONet product is used. There will be no update/resolution of this vulnerability in System 800xA. Instead, the strategy for ABB is to offer existing customers using VideONet a transfer to a new product, Camera Connect. This will be offered as soon as Camera Connect is available as a product.
An attacker who successfully exploited the vulnerability could, in the worst-case scenario, stop or manipulate the video feed.
There is no impact to other Operator station functions (graphics, trends, faceplates, etc.) and Control operations are not impacted at all.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/7paa012159</guid>
      <pubDate>Mon, 10 Feb 2025 00:30:00 +0000</pubDate>
    </item>
    <item>
      <title>9AKK108470A8565 — RMC-100 Vulnerability in the Web UI (REST Interface)</title>
      <link>https://cve.radiocsirt.org/vuln/9akk108470a8565</link>
      <description>&lt;p&gt;An update is available that resolves a vulnerability in the product versions listed as affected in this advisory.
An attacker who successfully exploited this vulnerability could cause the web UI to stop.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An update is available that resolves a vulnerability in the product versions listed as affected in this advisory.
An attacker who successfully exploited this vulnerability could cause the web UI to stop.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/9akk108470a8565</guid>
      <pubDate>Tue, 11 Mar 2025 00:30:00 +0000</pubDate>
    </item>
    <item>
      <title>SA24P015 — B&amp;R APROL Potential Privilege Escalation and Information Disclosure</title>
      <link>https://cve.radiocsirt.org/vuln/sa24p015</link>
      <description>&lt;p&gt;Updates are available that resolve privately reported vulnerabilities in the product versions listed as affected in this advisory.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploits these vulnerabilities could elevate privileges or gather sensitive information.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Updates are available that resolve privately reported vulnerabilities in the product versions listed as affected in this advisory.&lt;/p&gt;
&lt;p&gt;An attacker who successfully exploits these vulnerabilities could elevate privileges or gather sensitive information.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/sa24p015</guid>
      <pubDate>Mon, 24 Mar 2025 00:30:00 +0000</pubDate>
    </item>
    <item>
      <title>9AKK108470A9491 — ABB ACS880 +N8010 Drives CODESYS RTS Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/9akk108470a9491</link>
      <description>&lt;p&gt;Multiple vulnerabilities regarding the CODESYS Runtime System from CODESYS Group have been publicly reported. CODESYS Runtime System is utilized in the firmware of ABB ACS880 drives to provide IEC 61131-3 programming capabilities.&lt;/p&gt;
&lt;p&gt;These vulnerabilities could lead to out-of-bound memory access. Successful exploit may result in a denial-of-service condition or arbitrary code execution. Firmware updates are available that mitigate the publicly reported vulnerabilities of the product versions listed as affected in this advisory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities regarding the CODESYS Runtime System from CODESYS Group have been publicly reported. CODESYS Runtime System is utilized in the firmware of ABB ACS880 drives to provide IEC 61131-3 programming capabilities.&lt;/p&gt;
&lt;p&gt;These vulnerabilities could lead to out-of-bound memory access. Successful exploit may result in a denial-of-service condition or arbitrary code execution. Firmware updates are available that mitigate the publicly reported vulnerabilities of the product versions listed as affected in this advisory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/9akk108470a9491</guid>
      <pubDate>Wed, 26 Mar 2025 00:30:00 +0000</pubDate>
    </item>
  </channel>
</rss>
