Asea Brown Boveri Ltd. (ABB)
Self-Reporting Analysis
Of all the CVEs published by Asea Brown Boveri Ltd. (ABB) as a CNA, 43.8% affect products that Asea Brown Boveri Ltd. (ABB) develops as a vendor.
Of all the CVEs published that affect products developed by Asea Brown Boveri Ltd. (ABB), 75.2% are self-published by Asea Brown Boveri Ltd. (ABB) as a CNA.
Trends Over Time
The number and severity of CVEs published by Asea Brown Boveri Ltd. (ABB) over time
Top CVEs
All CVEs published by Asea Brown Boveri Ltd. (ABB) as a CNA, regardless of affected vendor or product.
276 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6298CRITICAL Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series
v3.08.01
; MATRIX Series
v3.08.01 allows Attacker to execute arbitrary code remotely | Jul 5, 2024 | 9.8 | 53 | NO | YES |
CVE-2024-48841CRITICAL Network access can be used to execute arbitrary code with elevated privileges.
This
issue affects FLXEON 9.3.4 and older. | Jan 27, 2025 | 10.0 | 43 | NO | YES |
CVE-2024-6209HIGH Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series
v3.08.01
; MATRIX Series
v3.08.01 allows Attacker to access files unauthorized | Jul 5, 2024 | 7.5 | 43 | NO | YES |
CVE-2025-14771CRITICAL Files or directories accessible to external parties vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24. | Jun 3, 2026 | 9.9 | 41 | NO | NO |
CVE-2025-14772HIGH Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24. | Jun 3, 2026 | 8.8 | 37 | NO | NO |
CVE-2024-48849CRITICAL Missing Origin Validation in WebSockets vulnerability in FLXEON. Session management was not sufficient to prevent unauthorized HTTPS requests. This issue affects FLXEON: through <= | Jan 29, 2025 | 9.4 | 37 | NO | YES |
CVE-2024-51550CRITICAL Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.
Affected products:
ABB ASPECT - Enterpr | Dec 5, 2024 | 9.8 | 37 | NO | YES |
CVE-2025-53187CRITICAL Due to an issue in configuration, code that was intended for debugging purposes was included in the market release of the ASPECT FW allowing an attacker to bypass authentication. T | Aug 11, 2025 | 9.8 | 36 | NO | NO |
CVE-2024-48852CRITICAL Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access.
This issue affects FLXEON t | Jan 29, 2025 | 9.4 | 36 | NO | YES |
CVE-2024-48845CRITICAL Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.
Affec | Dec 5, 2024 | 9.8 | 36 | NO | YES |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (276 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Asea Brown Boveri Ltd. (ABB) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Asea Brown Boveri Ltd. (ABB) as a CNA — matched by CVE ID, not by organization name.