Browse all 211 CVE security advisories affecting ABB. AI-powered Chinese analysis, POCs, and references for each vulnerability.
ABB operates as a global leader in electrification and industrial automation, providing critical infrastructure for power grids, manufacturing, and transportation. With 211 recorded Common Vulnerabilities and Exposures (CVEs), the company’s software and hardware ecosystems have historically been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from legacy industrial control systems and web-based management interfaces, exposing operational technology to potential compromise. Notable incidents include the discovery of hardcoded credentials and unpatched firmware in various PLCs and HMIs, which attackers have exploited to gain unauthorized network access. The sheer volume of CVEs highlights significant challenges in maintaining security across diverse, long-lifecycle products. While ABB implements security updates, the complexity of its integrated solutions continues to present persistent risks for industrial environments relying on its technology.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2019-18996 | ABB PB610 HMIStudio accepts malicious DLL file in an application — PB610 Panel Builder 600CWE-424 | 7.1 | High | 2019-12-18 |
| CVE-2019-18997 | PB610 HMISimulator provides interface with access to arbitrary files — PB610 Panel Builder 600CWE-424 | 4.3 | Medium | 2019-12-18 |
| CVE-2019-18995 | ABB PB610 HMISimulator does not check content-length of the HTTP request — PB610 Panel Builder 600CWE-20 | 4.3 | Medium | 2019-12-18 |
This page lists every published CVE security advisory associated with ABB. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.