Asea Brown Boveri Ltd. (ABB) is a global industrial automation and power-management company whose vulnerability footprint spans a substantial portfolio of programmable logic controllers, industrial switches, and embedded control systems deployed across critical infrastructure and manufacturing environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the high-value nature of industrial control targets. The exposure concentrates in the ASPECT and MATRIX product families and recurs through weakness classes including improper authentication, weak credential protection, insufficient input validation, and incorrect permission assignment—endemic to legacy industrial control design where direct network access was not originally assumed. Defenders should inventory ABB devices across their infrastructure, prioritize network segmentation around these systems, and treat authentication and access-control disclosures from this vendor as operationally urgent. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asea Brown Boveri Ltd. (ABB) over time
Of all the CVEs published by Asea Brown Boveri Ltd. (ABB) as a CNA, 43.8% affect products that Asea Brown Boveri Ltd. (ABB) develops as a vendor.
Of all the CVEs published that affect products developed by Asea Brown Boveri Ltd. (ABB), 75.2% are self-published by Asea Brown Boveri Ltd. (ABB) as a CNA.
Signals from CVEs in this vendor scope (161 CVEs).
161 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-7232HIGH The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value overflows a buffer and overwrites a Structured E | Jun 24, 2019 | 8.8 | 56 | NO | NO |
CVE-2024-6298CRITICAL Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series
v3.08.01
; MATRIX Series
v3.08.01 allows Attacker to execute arbitrary code remotely | Jul 5, 2024 | 9.8 | 53 | NO | YES |
CVE-2024-6209HIGH Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series
v3.08.01
; MATRIX Series
v3.08.01 allows Attacker to access files unauthorized | Jul 5, 2024 | 7.5 | 43 | NO | YES |
CVE-2025-14771CRITICAL Files or directories accessible to external parties vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24. | Jun 3, 2026 | 9.9 | 41 | NO | NO |
CVE-2025-14772HIGH Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24. | Jun 3, 2026 | 8.8 | 37 | NO | NO |
CVE-2024-51550CRITICAL Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.
Affected products:
ABB ASPECT - Enterpr | Dec 5, 2024 | 9.8 | 37 | NO | YES |
CVE-2024-48845CRITICAL Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.
Affec | Dec 5, 2024 | 9.8 | 36 | NO | YES |
CVE-2024-48840CRITICAL Unauthorized Access vulnerabilities allow Remote Code Execution.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02 | Dec 5, 2024 | 9.8 | 36 | NO | YES |
CVE-2024-48839CRITICAL Improper Input Validation vulnerability allows Remote Code Execution.
Affected products:
ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02 | Dec 5, 2024 | 9.8 | 36 | NO | YES |
CVE-2024-4007HIGH Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured. | Jul 1, 2024 | 8.8 | 36 | NO | YES |
Signals from CVEs in this vendor scope (161 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asea Brown Boveri Ltd. (ABB).
Media articles that mention a CVE ID that affects a product developed by Asea Brown Boveri Ltd. (ABB) — matched by CVE ID, not by vendor name.