CVE-2024-12429

MEDIUM

ABB AC500 V3 < 3.8.0 - Authenticated Path Traversal

Title source: llm
STIX 2.1

Description

An attacker who successfully exploited these vulnerabilities could grant read access to files. A vulnerability exists in the AC500 V3 version mentioned. A successfully authenticated attacker can use this vulnerability to read system wide files and configuration All AC500 V3 products (PM5xxx) with firmware version earlier than 3.8.0 are affected by this vulnerability.

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 33.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
ABB/AC500 V3 < 3.8.0
Published Jan 07, 2025
Tracked Since Feb 18, 2026