CVE-2025-10571
BaseFortify
Publication date: 2025-11-20
Last updated on: 2025-11-20
Assigner: Asea Brown Boveri Ltd. (ABB)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| abb | ability_edgenius | 3.2.0.0 |
| abb | ability_edgenius | 3.2.1.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-288 | The product requires authentication, but the product has an alternate path or channel that does not require authentication. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Authentication Bypass Using an Alternate Path or Channel in ABB Ability Edgenius versions 3.2.0.0 and 3.2.1.1. It allows an attacker to bypass the normal authentication mechanisms by exploiting an alternate path or channel, potentially gaining unauthorized access to the system.
How can this vulnerability impact me? :
The impact of this vulnerability is severe, as it allows attackers to bypass authentication without any privileges or user interaction, leading to complete compromise of confidentiality, integrity, and availability of the affected system.