PT-2025-42795 · Abb · Coresense™ Hm+1
Published
2025-10-20
·
Updated
2025-10-20
·
CVE-2025-3465
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ABB CoreSense™ HM versions through 2.3.1
ABB CoreSense™ M10 versions through 1.4.1.12
Description
An issue exists where a pathname is improperly limited to a restricted directory, potentially allowing path traversal. This affects ABB CoreSense™ HM and ABB CoreSense™ M10.
Recommendations
Update ABB CoreSense™ HM to a version later than 2.3.1.
Update ABB CoreSense™ M10 to a version later than 1.4.1.12.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coresense™ Hm
Coresense™ M10