CVE-2025-3395
published 2025-04-30CVE-2025-3395: Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.08%
0.4th percentile
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | automation_builder | <= 2.8.0 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv4.08.4HIGHCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ccmg-3338-rh6p: Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder
ghsa_unreviewed·2025-04-30
CVE-2025-3395 [HIGH] CWE-312 GHSA-ccmg-3338-rh6p: Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.
Red Hat
kernel: f2fs: fix to avoid out-of-boundary access in dnode page
vendor_redhat·2025-08-30·CVSS 7.1
CVE-2025-38677 [HIGH] kernel: f2fs: fix to avoid out-of-boundary access in dnode page
kernel: f2fs: fix to avoid out-of-boundary access in dnode page
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to avoid out-of-boundary access in dnode page
As Jiaming Zhang reported:
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x1c1/0x2a0 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0x17e/0x800 mm/kasan/report.c:480
kasan_report+0x147/0x180 mm/kasan/report.c:593
data_blkaddr fs/f2fs/f2fs.h:3053 [inline]
f2fs_data_blkaddr fs/f2fs/f2fs.h:3058 [inline]
f2fs_get_dnode_of_data+0x1a09/0x1c40 fs/f2fs/node.c:855
f2fs_reserve_block+0x53/0x310 fs/f2fs/data.c:1195
prepare_write_begin fs/f2fs/data.c:3395 [inline]
f2fs_write_begin+0xf39/0x2190 fs/f2fs/data.c:3594
generic_perform_write+0x2c7/0x910 mm/filemap.c:4
CISA ICS
ABB Automation Builder
cisa_ics·2025-05-13·CVSS 7.8
[HIGH] ABB Automation Builder
ICS Advisory
##
ABB Automation Builder
Release DateMay 13, 2025
Alert CodeICSA-25-133-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.5
- ATTENTION: Low attack complexity
- Vendor: ABB
- Equipment: Automation Builder
- Vulnerabilities: Incorrect Permission Assignment for Critical Resource
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to overrule the Automation Builder's user management.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Automation Builder are affected:
- Automation Builder: All versions
## 3.2 VULNERABILITY OVERVIEW
## 3.2.1 INCORRECT PERMISSION ASSIGNMENT FOR CRITICAL RESO
No detection rules found.
No public exploits indexed.
2025-04-30
Published