CVE-2025-3465
CVSS 7.1 HIGH: improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM… EPSS 0.2% (8º percentile).
Vulnerabilità · 135 giorni fa
Questi dispositivi ABB non si limitano a esporre percorsi file. Una falla di path traversal non autenticata può raggiungere directory ristrette ed escalare fino a una compromissione completa del sistema, quindi il dispositivo stesso potrebbe essere completamente compromesso anziché semplicemente esporre dati.
CVSS 7.1 HIGH: improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB CoreSense™ HM… EPSS 0.2% (8º percentile).
1 fonte che coprono questa storia
ABB CoreSense HM and CoreSense M10 | CISA
ABB CoreSense HM and CoreSense M10 Summary An update is available that resolves vulnerability in the product versions listed as affected in this advisory.
Part of the PlainSec briefing for 2026-05-20