CVE-2025-10205
8.8ABB · FLXEON
ABB FLXEON is susceptible to a vulnerability involving the use of a one-way hash with a predictable salt, potentially compromising credential integrity.
Executive summary
A critical security vulnerability in ABB FLXEON allows for the use of predictable salts in cryptographic hashing, which could facilitate unauthorized credential access.
Vulnerability
This vulnerability involves the use of a one-way hash with a predictable salt (CWE-759). The vulnerability is unauthenticated (AV:A/PR:N/UI:N), meaning an attacker with adjacent network access can potentially exploit the predictable salt to perform brute-force or dictionary attacks against stored credentials.
Business impact
The use of predictable salts significantly reduces the computational effort required to reverse password hashes. Successful exploitation could lead to unauthorized access to the FLXEON system, resulting in a complete loss of confidentiality and integrity for user credentials, potentially leading to broader system compromise or unauthorized control. Given the CVSS 8.8 score, this represents a high-severity risk that demands immediate attention to prevent credential harvesting.
Remediation
Immediate Action: Review the provided ABB security advisory (Document ID 9AKK108471A7121) to determine if a patch or configuration workaround is available for your specific deployment version.
Proactive Monitoring: Monitor network traffic for unusual authentication patterns and review system logs for repeated failed login attempts or unauthorized access requests.
Compensating Controls: Ensure that the FLXEON system is isolated within a secure network segment to restrict adjacent network access, thereby limiting the pool of potential attackers.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The vulnerability in ABB FLXEON represents a significant risk to credential security due to the predictable nature of the cryptographic salt implementation. Administrators should prioritize reviewing the official ABB documentation to identify if an update is available and implement network-level isolation to mitigate the risk of unauthorized access from adjacent network segments until a permanent resolution can be applied.
More ABB CVEs
Sources
Originally found and disclosed by ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure., per the CVE Program record.