Back

CRITICAL

Missing Authentication Vulnerability

Published Oct 20, 2025

Description

Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects . 

All firmware versions with the Serial Number from 2000 to 5166

Affected products

Remediation

Vendor solution

Workarounds are specific measures that a user can take to help block an attack. ABB has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they can help block known attack vectors. When a workaround reduces functionality, this is identified below as “Impact of workaround”.

– Physically disconnect the ethernet port if embedded web server is not being used.

Impact of workaround

The embedded web server and all its functionalities, incl. load monitoring, alarms, remote configuration, etc. will not be accessible. However, the product will continue functioning as normal based on configured control parameters.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ABB
Published Oct 20, 2025
Updated Oct 24, 2025
Reserved Aug 28, 2025

CISA Vulnrichment

Updated Oct 20, 2025

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner ABB
Published Oct 20, 2025
Updated Oct 24, 2025

GitHub

No data