Asea Brown Boveri Ltd. (ABB)

First CVE: Dec 18, 2019Active for: 7 years
276
CVEs Published
More CVEs Published than 83% of tracked CNAs
34.5
Avg CVEs / Year
More Avg CVEs / Year than 79% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 66% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Asea Brown Boveri Ltd. (ABB) as a CNA, 43.8% affect products that Asea Brown Boveri Ltd. (ABB) develops as a vendor.

43.8%
56.2%
Self-reported: 121Third-party: 155

Of all the CVEs published that affect products developed by Asea Brown Boveri Ltd. (ABB), 75.2% are self-published by Asea Brown Boveri Ltd. (ABB) as a CNA.

75.2%
24.8%
Self-published: 121Published by other CNAs: 40

Trends Over Time

The number and severity of CVEs published by Asea Brown Boveri Ltd. (ABB) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2019
6 years ago
Most Recent CVE
Jul 17, 2026
7 days ago

Top CVEs

All CVEs published by Asea Brown Boveri Ltd. (ABB) as a CNA, regardless of affected vendor or product.

276 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
Jul 5, 20249.853NOYES
Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older.
Jan 27, 202510.043NOYES
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized
Jul 5, 20247.543NOYES
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
Jun 3, 20269.941NONO
Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
Jun 3, 20268.837NONO
Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <=
Jan 29, 20259.437NOYES
Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.  Affected products: ABB ASPECT - Enterpr
Dec 5, 20249.837NOYES
Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. T
Aug 11, 20259.836NONO
Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON t
Jan 29, 20259.436NOYES
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.  Affec
Dec 5, 20249.836NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA276 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local60 (21.7%)
Network183 (66.3%)
Unknown0 (0.0%)
Physical4 (1.4%)
Adjacent Network26 (9.4%)
Attack Complexity
Low249 (90.2%)
High27 (9.8%)
Unknown0 (0.0%)
User Interaction
None236 (85.5%)
Unknown0 (0.0%)
Required38 (13.8%)
Privileges Required
Low100 (36.2%)
High33 (12.0%)
None143 (51.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (276 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
16 CVEs
5.8% of CVEs· 96th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Asea Brown Boveri Ltd. (ABB) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Asea Brown Boveri Ltd. (ABB) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs