ABB AC500 V3
cpe:2.3:o:abb:ac500_cpu_firmware:*:*:*:*:*:*:*
- < 3.8.0
A command execution vulnerability has been identified in ABB AC500 V3 products (PM5xxx) with firmware versions prior to 3.8.0. This vulnerability arises from a directory traversal issue (CVE-2024-12429), which allows a successfully authenticated attacker to inject arbitrary commands into a specially crafted file. The injected commands are then executed by the root user.
Exploitation of this vulnerability could lead to unauthorized command execution with root privileges.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.