Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Asea Brown Boveri Ltd. (ABB)

First CVE: Sep 29, 2008Active for: 18 yearsTotal CVEs: 161
49.1
VTI Score
High

Asea Brown Boveri Ltd. (ABB) is a global industrial automation and power-management company whose vulnerability footprint spans a substantial portfolio of programmable logic controllers, industrial switches, and embedded control systems deployed across critical infrastructure and manufacturing environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the high-value nature of industrial control targets. The exposure concentrates in the ASPECT and MATRIX product families and recurs through weakness classes including improper authentication, weak credential protection, insufficient input validation, and incorrect permission assignment—endemic to legacy industrial control design where direct network access was not originally assumed. Defenders should inventory ABB devices across their infrastructure, prioritize network segmentation around these systems, and treat authentication and access-control disclosures from this vendor as operationally urgent. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
161
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Asea Brown Boveri Ltd. (ABB) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 29, 2008
17 years ago
Most Recent CVE
Jun 3, 2026
51 days ago

Self-Reporting Analysis

Of all the CVEs published by Asea Brown Boveri Ltd. (ABB) as a CNA, 43.8% affect products that Asea Brown Boveri Ltd. (ABB) develops as a vendor.

43.8%
56.2%
Self-reported: 121 (43.8%)
Third-party: 155 (56.2%)

Of all the CVEs published that affect products developed by Asea Brown Boveri Ltd. (ABB), 75.2% are self-published by Asea Brown Boveri Ltd. (ABB) as a CNA.

75.2%
24.8%
Self-published: 121 (75.2%)
Other CNAs: 40 (24.8%)

Products(391 total)

Top CVEs

Signals from CVEs in this vendor scope (161 CVEs).

161 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-7232HIGH
The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host header value overflows a buffer and overwrites a Structured E
Jun 24, 20198.856NONO
CVE-2024-6298CRITICAL
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code remotely
Jul 5, 20249.853NOYES
CVE-2024-6209HIGH
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized
Jul 5, 20247.543NOYES
CVE-2025-14771CRITICAL
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
Jun 3, 20269.941NONO
CVE-2025-14772HIGH
Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
Jun 3, 20268.837NONO
CVE-2024-51550CRITICAL
Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device.  Affected products: ABB ASPECT - Enterpr
Dec 5, 20249.837NOYES
CVE-2024-48845CRITICAL
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access.  Affec
Dec 5, 20249.836NOYES
CVE-2024-48840CRITICAL
Unauthorized Access vulnerabilities allow Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
Dec 5, 20249.836NOYES
CVE-2024-48839CRITICAL
Improper Input Validation vulnerability allows Remote Code Execution.  Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
Dec 5, 20249.836NOYES
CVE-2024-4007HIGH
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
Jul 1, 20248.836NOYES
View all 161 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products161 CVEs
22%
52%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local43 (26.7%)
Network94 (58.4%)
Unknown5 (3.1%)
Physical0 (0.0%)
Adjacent Network19 (11.8%)
Attack Complexity
Low151 (93.8%)
High5 (3.1%)
Unknown5 (3.1%)
User Interaction
None139 (86.3%)
Unknown5 (3.1%)
Required17 (10.6%)
Privileges Required
Low64 (39.8%)
High3 (1.9%)
None89 (55.3%)
Unknown5 (3.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (161 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
7.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Asea Brown Boveri Ltd. (ABB).

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Asea Brown Boveri Ltd. (ABB) — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Asea Brown Boveri Ltd. (ABB)'s Products

View all 7 CNAs →

Top CWEs