ABB EIBPORT building management systems running firmware prior to version 3.9.2 contain a high-severity Cross-Site Scripting (XSS) vulnerability (CVE-2021-22291). Successful exploitation allows attackers to steal session IDs, leading to unauthenticated device access, sensitive information disclosure, and unauthorized configuration changes.
ABB
8 posts
ABB EIBPORT ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) ABB B&R Automation Runtime contains a critical Improper Resource Locking vulnerability (CVE-2025-3450) within its System Diagnostics Manager (SDM) component. An unauthenticated, remote attacker can exploit this flaw by sending a specially crafted message over the network to delete data, resulting in a denial-of-service condition that halts the affected system node.
Cyber Centre Daily Advisory Digest — 2026-05-26 (2 advisories) The Canadian Centre for Cyber Security issued two advisories concerning control systems. Moxa addressed multiple Linux kernel vulnerabilities (Copy Fail and Dirty Frag) across various product series, while ABB mitigated a concurrent connection handling issue in its PPT30 OPC-UA Server.
ABB Ability Camera Connect ABB Ability Camera Connect versions 1.5.0.14 and earlier contain multiple critical and high-severity vulnerabilities due to an outdated bundled VLC media player component. These flaws, including buffer overflows and integer underflows, could allow an attacker to execute arbitrary code or cause a denial of service via crafted media files. The risk is significantly reduced as the application is typically deployed in isolated, air-gapped ICS environments.
ABB LVS MConfig ABB LVS MConfig versions 1.4.9.21 and prior contain a high-severity vulnerability (CVE-2025-9970) where user credentials are stored in cleartext in application memory. An attacker with local or physical access to the host machine can export a memory dump during runtime to extract these passwords, potentially allowing unauthorized modification of low voltage switchgear components.
ABB Terra AC ABB Terra AC wallbox EV chargers are affected by a heap-based buffer overflow vulnerability (CVE-2025-5517, CVSS 6.8) due to improper length validation of OCPP fields. An attacker who hijacks the OCPP backend or intercepts unencrypted HTTP traffic can send crafted messages to execute arbitrary code, alter firmware, or cause a denial of service.
ABB Terra AC Wallbox ABB Terra AC Wallbox (JP) versions 1.8.33 and prior are affected by multiple buffer overflow vulnerabilities (CVE-2025-10504, CVE-2025-12142, CVE-2025-12143) with a CVSS score of 6.1. Successful exploitation requires a threat actor to hijack the Bluetooth connection, potentially allowing them to pollute memory, alter firmware behavior, and take remote control of the device.
ABB B&R Automation Studio ABB has disclosed multiple vulnerabilities in B&R Automation Studio versions prior to 6.5, stemming from an outdated third-party SQLite component. These flaws, which include heap-based buffer overflows and integer overflows, could potentially be exploited to achieve remote code execution, data exposure, or denial of service, though no active exploitation has been observed.