CVE-2025-3465
CVSS 7.1 HIGH: improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM… EPSS 0.2% (8º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Questi dispositivi ABB non si limitano a esporre percorsi file. Una falla di path traversal non autenticata può raggiungere directory ristrette ed escalare fino a una compromissione completa del sistema, quindi il dispositivo stesso potrebbe essere completamente compromesso anziché semplicemente esporre dati.
1 fonte · 19 mag
CVSS 7.1 HIGH: improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM… EPSS 0.2% (8º percentile).
CISA Advisories
ABB CoreSense HM and CoreSense M10 | CISA
ABB CoreSense HM and CoreSense M10 Summary An update is available that resolves vulnerability in the product versions listed as affected in this advisory.
originalePart of the PlainSec briefing for 2026-05-19
Every edition of this story: Difetto in ABB CoreSense può compromettere completamente i dispositivi