PT-2025-42789 · Abb · Als-Mini-S4 Ip+1

Published

2025-10-20

·

Updated

2025-11-27

·

CVE-2025-9574

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ABB ALS-mini-s4 IP ABB ALS-mini-s8 IP versions with Serial Number 2000 through 5166
Description A critical issue exists in ABB ALS-mini-s4 IP and ABB ALS-mini-s8 IP devices where certain critical functions can be accessed without authentication. This means that no credentials, such as passwords, are required to potentially manipulate these functions. The affected devices have Serial Numbers ranging from 2000 to 5166.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-13969
CVE-2025-9574

Affected Products

Als-Mini-S4 Ip
Als-Mini-S8 Ip