CVE-2025-10207
7.2ABB · FLXEON
ABB FLXEON is susceptible to an improper input validation vulnerability that may lead to significant security compromise.
Executive summary
The ABB FLXEON product is affected by an input validation vulnerability that could allow an authenticated attacker with high privileges to cause a total impact on system integrity, confidentiality, and availability.
Vulnerability
This vulnerability, classified as CWE-1287, involves the improper validation of specified input types within the FLXEON software. The vulnerability requires the attacker to possess high privileges (PR:H) to successfully exploit the flaw.
Business impact
The exploitation of this vulnerability poses a severe risk to operational continuity, as it allows for a total impact on the affected system. Given the CVSS score of 7.2, this vulnerability is categorized as High severity, indicating that successful exploitation could result in unauthorized data access or disruption of critical business processes. Organizations relying on FLXEON for industrial or infrastructure management must prioritize this risk to prevent potential service degradation or unauthorized control.
Remediation
Immediate Action: Consult the official ABB security advisory to identify and apply the necessary firmware or software updates as soon as they become available.
Proactive Monitoring: Monitor system access logs for any unauthorized configuration changes or anomalous activity originating from high-privilege user accounts.
Compensating Controls: Implement strict network segmentation and restrict administrative access to the management interfaces to minimize the attack surface until a patch is applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this flaw requires diligent monitoring of the ABB security portal for the release of a definitive patch. Security teams should ensure that access control lists are hardened to prevent unauthorized high-privilege access, which is a prerequisite for exploiting this vulnerability. Immediate remediation is required upon the release of vendor updates to mitigate the risk of total system compromise.
More ABB CVEs
Sources
Originally found and disclosed by ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure., per the CVE Program record.