CVE-2025-6072
BaseFortify
Publication date: 2025-07-03
Last updated on: 2025-07-08
Assigner: Asea Brown Boveri Ltd. (ABB)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-121 | A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function). |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a stack-based buffer overflow in ABB RMC-100 and ABB RMC-100 LITE devices. It occurs when the REST interface is enabled and an attacker who has access to the control network exploits another vulnerability (CVE-2025-6074) to use a JSON configuration to overflow the expiration date field, potentially causing unexpected behavior or crashes.
How can this vulnerability impact me? :
The vulnerability can lead to a stack-based buffer overflow, which may allow an attacker to cause denial of service or potentially execute arbitrary code on the affected device. This can disrupt the normal operation of the ABB RMC-100 or RMC-100 LITE devices, impacting system availability and reliability.