ABB CoreSense Flaw Can Fully Compromise Devices

These ABB devices are not just leaking file paths. An unauthenticated path traversal flaw can reach restricted directories and escalate to complete system compromise, so the device itself may be fully owned rather than simply exposing data. CISA says CVE-2025-3465 affects ABB CoreSense HM <=2.3.1 and CoreSense M10 <=1.4.1.12, with fixes in CoreSense HM v2.3.4 and CoreSense M10 v1.4.1.31. The affected products are used in food and agriculture, commercial facilities, and critical manufacturing, and the advisory also warns of sensitive-information exposure. For OT environments, the risk is beyond directory disclosure. A compromise of these units can reveal configuration and operational data and create a foothold into the surrounding control environment.

Part of the PlainSec briefing for 2026-05-20

Sources