ABB
ABB Rtu500: vulnerabilidades y CVE
ABB Rtu500 tiene 10 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses3
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8067 | Media (6.5) | 0.32% | — | 29 sept 2026 | An improper authorization vulnerability in the end-of-life versions of RTU500’s web application allows an authenticated user to trigger the RTU500 to reboot through the reset endpoint. Successful exploitation could… |
| CVE-2026-17539 | Media (5.9) | 0.27% | — | 3 sept 2026 | RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can cause a BCI_IEC104… |
| CVE-2026-8479 | Media (6.9) | 0.25% | — | 26 may 2026 | IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is… |
| CVE-2025-1445 | Alta (8.7) | 0.33% | — | 25 mar 2025 | A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiation of an open IEC61850 TLS connection takes place in specific timing situations, when IEC61850… |
| CVE-2024-12169 | Alta (8.7) | 0.40% | — | 25 mar 2025 | A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart the affected CMU. This… |
| CVE-2024-11499 | Media (6.9) | 0.24% | — | 25 mar 2025 | A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are… |
| CVE-2024-10037 | Media (5.9) | 0.34% | — | 25 mar 2025 | A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crafted message sequence is executed on a WebSocket connection. An attacker must… |
| CVE-2024-2617 | Alta (7.2) | 0.66% | — | 30 abr 2024 | A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully… |
| CVE-2024-1532 | Media (6.8) | 0.57% | — | 27 mar 2024 | A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized… |
| CVE-2024-1531 | Alta (8.2) | 0.45% | — | 27 mar 2024 | A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content in the RTU500 system log, if an authorized user… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de ABB
Nexus-2128 Firmware · 29Nexus-264 Firmware · 29Aspect-ent-2 Firmware · 29Matrix-264 Firmware · 29Matrix-296 Firmware · 29Matrix-216 Firmware · 29Aspect-ent-12 Firmware · 29Aspect-ent-256 Firmware · 29Aspect-ent-96 Firmware · 29Matrix-11 Firmware · 29Matrix-232 Firmware · 29Nexus-3-2128 Firmware · 29