Browse all 211 CVE security advisories affecting ABB. AI-powered Chinese analysis, POCs, and references for each vulnerability.
ABB operates as a global leader in electrification and industrial automation, providing critical infrastructure for power grids, manufacturing, and transportation. With 211 recorded Common Vulnerabilities and Exposures (CVEs), the company’s software and hardware ecosystems have historically been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from legacy industrial control systems and web-based management interfaces, exposing operational technology to potential compromise. Notable incidents include the discovery of hardcoded credentials and unpatched firmware in various PLCs and HMIs, which attackers have exploited to gain unauthorized network access. The sheer volume of CVEs highlights significant challenges in maintaining security across diverse, long-lifecycle products. While ABB implements security updates, the complexity of its integrated solutions continues to present persistent risks for industrial environments relying on its technology.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2020-24675 | Weak Authentication in Symphony Plus — ABB Ability™ Symphony® Plus OperationsCWE-287 | 9.8 | Critical | 2020-12-22 |
| CVE-2020-24673 | SQL Injection in Symphony Plus — ABB Ability™ Symphony® Plus OperationsCWE-89 | 9.8 | Critical | 2020-12-22 |
| CVE-2020-24674 | Improper Authorization in Symphony Plus — ABB Ability™ Symphony® Plus OperationsCWE-285 | 8.8 | High | 2020-12-22 |
| CVE-2020-24683 | Authentication Bypass in Symphony Plus — ABB Ability™ Symphony® Plus OperationsCWE-602 | 9.8 | Critical | 2020-12-22 |
| CVE-2020-24680 | Improper Credential Storage in Symphony Plus — ABB Ability™ Symphony® Plus OperationsCWE-255 | 7.0 | High | 2020-12-22 |
| CVE-2020-24679 | Denial of Service attack on Symphony Plus — ABB Ability™ Symphony® Plus OperationsCWE-20 | 7.5 | High | 2020-12-22 |
| CVE-2020-24677 | Insecure Web Service in Symphony Plus — ABB Ability™ Symphony® Plus OperationsCWE-754 | 8.8 | High | 2020-12-22 |
| CVE-2020-24676 | Insecure Windows Services in Symphony Plus — ABB Ability™ Symphony® Plus OperationsCWE-274 | 7.8 | High | 2020-12-22 |
| CVE-2020-24678 | Potential Privilege Escalation in Symphony Plus — ABB Ability™ Symphony® Plus OperationsCWE-269 | 8.8 | High | 2020-12-22 |
This page lists every published CVE security advisory associated with ABB. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.