CVE-2025-4676
Authentication Bypass in ABB WebPro SNMP Card PowerValue
Publication date: 2026-01-07
Last updated on: 2026-01-07
Assigner: Asea Brown Boveri Ltd. (ABB)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| abb | webpro_snmp_card_powervalue | to 1.1.8.K (inc) |
| abb | webpro_snmp_card_powervalue_ul | to 1.1.8.K (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-303 | The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Incorrect Implementation of the Authentication Algorithm in ABB WebPro SNMP Card PowerValue and PowerValue UL devices, affecting versions through 1.1.8.K. It means the authentication mechanism used by these devices is flawed, potentially allowing unauthorized access.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to the affected devices, potentially allowing attackers to compromise device integrity, confidentiality, and availability. This could result in unauthorized control or disruption of the devices' functions.