Path Traversal Vulnerability in ABB CoreSense Products
CVE-2025-3465

8.2HIGH

Key Information:

Vendor

Abb

Vendor
CVE Published:
20 October 2025

What is CVE-2025-3465?

The vulnerability in ABB CoreSenseā„¢ HM and CoreSenseā„¢ M10 arises from improper handling of pathname restrictions, allowing unauthorized access to restricted directories. This flaw could potentially enable an attacker to manipulate file paths to access sensitive files or execute arbitrary commands, posing significant security risks. Users are advised to update to the latest versions to mitigate this issue effectively.

Affected Version(s)

CoreSenseā„¢ HM 0 <= 2.3.1

CoreSenseā„¢ M10 0 <= 1.4.1.12

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-3465 : Path Traversal Vulnerability in ABB CoreSense Products