PatchSiren

ABB CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ABB CVE published 2025-07-03

CVE-2025-6073

CVE-2025-6073 is a high-severity ABB RMC-100 issue that can overflow the username or password buffer, but only under a specific chain of conditions: the REST interface must be enabled, an attacker must have access to the control network, user/password broker authentication must be enabled, and CVE-2025-6074 must also be exploited. ABB and CISA list fixed builds for affected RMC-100 and RMC-100 LITE versio [truncated]

HIGH ABB CVE published 2025-07-03

CVE-2025-6072

CVE-2025-6072 is a high-severity ABB RMC-100 / RMC-100 LITE issue in the REST interface path. According to the advisory, if the REST interface is enabled and an attacker already has access to the control network, exploitation of CVE-2025-6074 can let the attacker use JSON configuration input to overflow the expiration-date field. ABB provides fixed releases for affected RMC-100 and RMC-100 LITE versions.

MEDIUM ABB CVE published 2025-07-03

CVE-2025-6071

CVE-2025-6071 is a medium-severity confidentiality issue affecting ABB RMC-100 and RMC-100 LITE. According to the CISA CSAF advisory, an attacker may gain access to salted information and use it to decrypt MQTT information. ABB and CISA list fixed releases for the affected product lines, and the advisory was later republished with updated vendor information.

HIGH ABB CVE published 2025-04-30

CVE-2025-3394

CVE-2025-3394 is a high-severity issue in ABB Automation Builder project handling. CISA says the product stores user management information in the project file; although password data is fully encrypted, a specially crafted project file can cause user management to be overruled. For organizations that exchange, store, or archive Automation Builder projects, this is primarily an integrity and access-control concern.

MEDIUM ABB CVE published 2025-04-07

CVE-2023-40217

CVE-2023-40217 is a network-reachable information-disclosure issue affecting ABB M2M Gateway ARM600 and ABB M2M Gateway SW. In a narrow timing window, buffered data may remain readable before TLS client-certificate authentication is initiated, which can expose limited sensitive information from the server.

HIGH ABB CVE published 2025-04-07

CVE-2023-38408

CVE-2023-38408 is a high-severity OpenSSH ssh-agent flaw that CISA mapped to ABB M2M Gateway ARM600 and ABB M2M Gateway SW in its 2025-04-07 advisory. The issue is tied to an insufficiently trustworthy search path in the PKCS#11 feature and can lead to remote code execution when agent forwarding is used by an authenticated user on an attacker-controlled system. For ABB environments, the main risk is where [truncated]

HIGH ABB CVE published 2025-04-07

CVE-2023-32233

ABB’s 2025-04-07 CSAF advisory maps CVE-2023-32233 to ABB M2M Gateway ARM600 and ABB M2M Gateway SW deployments in the affected version ranges. The underlying Linux kernel nf_tables use-after-free is a local privilege-escalation issue that can enable arbitrary kernel memory read/write and root access on affected systems.

MEDIUM ABB CVE published 2025-04-07

CVE-2023-24329

CVE-2023-24329 is a medium-severity issue disclosed in ABB’s CISA advisory for ABB M2M Gateway ARM600 and related ABB M2M Gateway SW versions. The vulnerability is in Python’s urllib.parse handling of URLs that begin with blank characters, which can let an authenticated attacker bypass blocklisting checks and add or modify data.

HIGH ABB CVE published 2025-04-07

CVE-2023-22809

CVE-2023-22809 is a sudoedit flaw that can let a local attacker append extra files to the edit list via SUDO_EDITOR, VISUAL, or EDITOR, creating a path to privilege escalation. In CISA advisory ICSA-25-105-08, the issue is mapped to ABB M2M Gateway ARM600 and ABB M2M Gateway SW, with affected versions called out in the advisory published on 2025-04-07.

MEDIUM ABB CVE published 2025-04-07

CVE-2022-43750

CVE-2022-43750 is a Linux kernel usbmon issue that can corrupt the monitor’s internal memory. In the supplied ABB advisory, CISA maps the CVE to ABB M2M Gateway ARM600 and ABB M2M Gateway SW, with affected version ranges listed in the source. The stated outcomes are denial of service and information disclosure, and the supplied CVSS vector indicates a local attack path requiring high privileges.

HIGH ABB CVE published 2025-04-07

CVE-2022-42898

CVE-2022-42898 is a high-severity advisory affecting ABB M2M Gateway ARM600 and ABB M2M Gateway SW deployments listed in the supplied CSAF source. The source describes the issue as PAC parsing in krb5 with integer overflows that may lead to denial of service. The advisory focuses on exposure reduction and OT hardening measures, and the supplied corpus does not include a fixed version or patch release.

MEDIUM ABB CVE published 2025-04-07

CVE-2022-42703

CVE-2022-42703 is a Linux kernel use-after-free in mm/rmap.c related to leaf anon_vma double re-use. In the supplied CISA/ABB advisory, it is mapped to ABB M2M Gateway ARM600 firmware 4.1.2 through 5.0.3 and ABB M2M Gateway SW 5.0.1 through 5.0.3. The advisory indicates the issue could cause a system crash or elevation of privileges, with local exploitation and high privileges required.

HIGH ABB CVE published 2025-04-07

CVE-2022-41974

CVE-2022-41974 is a HIGH-severity local privilege-escalation issue in ABB M2M Gateway ARM600 and related ABB M2M Gateway SW. According to CISA’s CSAF advisory published on 2025-04-07, a local user who can write to UNIX domain sockets may bypass access controls, manipulate the multipath setup, and potentially gain root privileges.

HIGH ABB CVE published 2025-04-07

CVE-2022-40674

CVE-2022-40674 is a high-severity local privilege-escalation issue affecting ABB M2M Gateway products, including ARM600 firmware versions 4.1.2 through 5.0.3 and ABB M2M Gateway SW versions 5.0.1 through 5.0.3. According to the CISA/ABB advisory published on 2025-04-07, a local user who can write to UNIX domain sockets may bypass access controls and manipulate the multipath setup, which can lead to root-l [truncated]

HIGH ABB CVE published 2025-04-07

CVE-2022-37434

CVE-2022-37434 is a zlib flaw in inflate() that can trigger a heap-based buffer over-read or buffer overflow when processing a large gzip header extra field. In the supplied CISA advisory, ABB maps the issue to ABB M2M Gateway ARM600 firmware versions 4.1.2 through 5.0.3 and ABB M2M Gateway SW versions 5.0.1 through 5.0.3. The vendor description says an authenticated attacker could potentially reveal sens [truncated]

HIGH ABB CVE published 2025-04-07

CVE-2022-2964

CISA’s ABB M2M Gateway advisory maps CVE-2022-2964 to ABB ARM600 firmware and ABB M2M Gateway SW releases. The issue is described as a flaw in the Linux kernel driver for ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet devices, with multiple out-of-bounds reads and possible out-of-bounds writes. Because the affected products and versions are explicitly listed by ABB/CISA, operators should treat this [truncated]

MEDIUM ABB CVE published 2025-04-07

CVE-2022-29154

CVE-2022-29154 is a remote file-overwrite vulnerability affecting ABB M2M Gateway products, including ARM600. According to the CISA CSAF advisory published on 2025-04-07, a malicious rsync server can overwrite arbitrary files in the rsync client target directory and subdirectories. The advisory assigns CVSS 3.1 6.8 MEDIUM, with network access, low privileges, no user interaction, and high integrity and av [truncated]

HIGH ABB CVE published 2025-04-07

CVE-2022-2526

CVE-2022-2526 is a use-after-free vulnerability affecting ABB M2M Gateway products, including ARM600. CISA published advisory ICSA-25-105-08 on 2025-04-07 for this issue. The flaw is described as a reference-counting error in resolved-dns-stream.c: on_stream_io() and dns_stream_complete() do not increment the DnsStream object's reference count, so later functions and callbacks can dereference freed memory [truncated]

MEDIUM ABB CVE published 2025-04-07

CVE-2020-22218

CVE-2020-22218 is an out-of-bounds memory access issue in libssh2’s _libssh2_packet_add function that ABB reported through CISA for its M2M Gateway ARM600 product line. In the supplied advisory, the primary impact is a possible system crash, and the attack requires an authenticated attacker. ABB/CISA’s published mitigations focus on reducing exposure of the ARM600 to the internet and hardening network acc [truncated]

MEDIUM ABB CVE published 2025-04-07

CVE-2016-10009

CVE-2016-10009 is a medium-severity OpenSSH issue that CISA mapped to ABB M2M Gateway ARM600 and ABB M2M Gateway SW in its 2025-04-07 CSAF advisory. The vulnerability affects ssh-agent behavior when a forwarded agent socket can be controlled, potentially allowing execution of local PKCS#11 modules. In ABB’s advisory context, the practical risk is highest for systems that expose management or remote-access [truncated]

MEDIUM ABB CVE published 2025-04-07

CVE-2013-0169

CISA’s ABB M2M Gateway advisory published on 2025-04-07 maps CVE-2013-0169 to ARM600 firmware 4.1.2 through 5.0.3 and ABB M2M Gateway SW 5.0.1 through 5.0.3. The issue is the Lucky Thirteen timing side-channel in TLS 1.1/1.2 and DTLS 1.0/1.2 CBC padding and MAC processing, which can support distinguishing and plaintext-recovery attacks through statistical analysis of packet timing. ABB’s published guidanc [truncated]

LOW ABB CVE published 2025-04-07

CVE-2012-4929

CVE-2012-4929 is the CRIME-style TLS compression weakness: when TLS 1.2 or earlier compresses data without hiding the length of the unencrypted content, a man-in-the-middle attacker can infer plaintext HTTP header data by comparing response lengths across repeated guesses. In the supplied CISA advisory, ABB maps this issue to ABB M2M Gateway ARM600 firmware 4.1.2 through 5.0.3 and ABB M2M Gateway SW 5.0.1 [truncated]

MEDIUM ABB CVE published 2025-04-07

CVE-1999-0524

CVE-1999-0524 covers an ICMP Timestamp Request remote date disclosure issue affecting ABB M2M Gateway ARM600 and ABB M2M Gateway SW. According to CISA’s advisory, the affected ranges are ARM600 firmware 4.1.2 through 5.0.3 and ABB M2M Gateway SW 5.0.1 through 5.0.3. The issue is network-reachable and exposes information about system time, so it is primarily a confidentiality concern rather than an integri [truncated]

HIGH ABB CVE published 2025-03-11

CVE-2022-24999

CVE-2022-24999 is a high-severity availability issue in ABB RMC-100 and RMC-100 LITE web UI REST interface components. According to the CISA CSAF advisory published on 2025-03-11, a specially crafted message can cause the Node process to hang, requiring the REST interface to be disabled and re-enabled to restore service. ABB lists fixed customer packages for both affected product lines.

CRITICAL ABB CVE published 2025-02-05

CVE-2024-51547

CVE-2024-51547 is a critical firmware credential exposure issue affecting ABB ASPECT®-Enterprise and related NEXUS/MATRIX series products. CISA’s advisory published on 2025-02-05 states that several hard-coded credentials for product internal use are stored in the firmware as plain text, with affected releases including ASP-ENT-x, NEX-2x, NEXUS-3-x, and MAT-x up to version 3.08.03. The advisory rates the [truncated]

CRITICAL ABB CVE published 2025-01-23

CVE-2024-48852

CISA’s advisory for ABB FLXEON Controllers says some information may be improperly disclosed through HTTPS access in firmware 9.3.4 and earlier. The vendor’s remediation is to upgrade to 9.3.5 or later, avoid direct Internet exposure, and use secure remote-access controls such as a properly maintained VPN.

CRITICAL ABB CVE published 2025-01-23

CVE-2024-48849

CVE-2024-48849 is a critical ABB advisory affecting FLXEON-controller family products and related firmware versions at or below 9.3.4. CISA published the advisory on 2025-01-23 and later revised it on 2025-02-14. The issue is described as insufficient session management to prevent unauthorized HTTPS requests, which can expose affected systems to unauthorized actions over the network. The source remediatio [truncated]

CRITICAL ABB CVE published 2025-01-23

CVE-2024-48841

CVE-2024-48841 is a critical ABB FLXEON controller vulnerability that allows network-based execution of arbitrary code with elevated privileges. The advisory affects FLXEON products at firmware 9.3.4 and earlier, with CISA listing FBXi, FBVi, FBTi, and CBXi firmware as impacted. ABB and CISA recommend immediate exposure reduction and firmware upgrade to 9.3.5 or later.

CRITICAL ABB CVE published 2024-07-03

CVE-2024-6784

Server-Side Request Forgery (SSRF) vulnerabilities in ABB ASPECT systems enable authenticated attackers to access unauthorized internal resources and disclose sensitive information. The vulnerability affects multiple product lines including ASPECT-Enterprise, NEXUS Series, and MATRIX Series running firmware version 3.08.02 and earlier. CISA published initial advisory ICSA-25-007-01 on July 3, 2024, with s [truncated]

CRITICAL ABB CVE published 2024-07-03

CVE-2024-6516

Cross-site scripting (XSS) vulnerabilities in ABB ASPECT building automation systems allow malicious script injection into client browsers. Affected versions include ASPECT-Enterprise (ASP-ENT-x), NEXUS Series (NEX-2x, NEXUS-3-x), and MATRIX Series (MAT-x) running firmware 3.08.02 and earlier. The vulnerability was disclosed on July 3, 2024, with vendor fixes becoming available in subsequent months—versio [truncated]