CVE-2025-4676

8.8

ABB · WebPro SNMP Card

An incorrect implementation of the authentication algorithm in ABB WebPro SNMP Cards allows for potential security bypasses.

Executive summary

A critical authentication vulnerability in ABB WebPro SNMP cards exposes affected power management systems to unauthorized control and potential service disruption.

Vulnerability

The device suffers from an incorrect implementation of the authentication algorithm, classified under CWE-303. This flaw allows an unauthenticated attacker, positioned on the adjacent network, to bypass security controls and achieve a high impact on system integrity and availability.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high level of severity due to the potential for total impact on system availability and integrity. Successful exploitation could allow attackers to manipulate power management settings, leading to unauthorized system shutdowns or the disruption of critical infrastructure services, which may result in significant operational downtime and reputational damage.

Remediation

Immediate Action: Review the official ABB security advisory and apply the latest firmware updates as soon as they are released by the vendor.

Proactive Monitoring: Monitor network traffic directed toward SNMP management interfaces for anomalous patterns and review system access logs for unauthorized authentication attempts.

Compensating Controls: Restrict access to the SNMP management interface by implementing strict network segmentation and firewall rules that limit communication to authorized management workstations only.

Exploitation status

Public Exploit Available: exploit_available (unknown)

Analyst recommendation

Given the high severity of this vulnerability and its potential to impact physical power management systems, administrators should treat this as a priority update. Organizations must restrict network access to affected SNMP cards immediately while awaiting specific patch deployment instructions from ABB to mitigate the risk of unauthorized access.

More ABB CVEs

Sources