Path Traversal Vulnerability in ABB CoreSense Products
CVE-2025-3465
8.2HIGH
What is CVE-2025-3465?
The vulnerability in ABB CoreSense⢠HM and CoreSense⢠M10 arises from improper handling of pathname restrictions, allowing unauthorized access to restricted directories. This flaw could potentially enable an attacker to manipulate file paths to access sensitive files or execute arbitrary commands, posing significant security risks. Users are advised to update to the latest versions to mitigate this issue effectively.
Affected Version(s)
CoreSense⢠HM 0 <= 2.3.1
CoreSense⢠M10 0 <= 1.4.1.12