Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects . 

All firmware versions with the Serial Number from 2000 to 5166
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Workarounds are specific measures that a user can take to help block an attack. ABB has tested the following workarounds. Although these workarounds will not correct the underlying vulnerability, they can help block known attack vectors. When a workaround reduces functionality, this is identified below as “Impact of workaround”. – Physically disconnect the ethernet port if embedded web server is not being used. Impact of workaround The embedded web server and all its functionalities, incl. load monitoring, alarms, remote configuration, etc. will not be accessible. However, the product will continue functioning as normal based on configured control parameters.

History

Mon, 20 Oct 2025 20:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Oct 2025 17:00:00 +0000

Type Values Removed Values Added
Description Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects .  All firmware versions with the Serial Number from 2000 to 5166
Title Missing Authentication Vulnerability
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:H/S:N/AU:Y/R:U/V:D/RE:M/U:Red'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2025-10-20T17:32:51.170Z

Reserved: 2025-08-28T10:04:01.947Z

Link: CVE-2025-9574

cve-icon Vulnrichment

Updated: 2025-10-20T17:32:43.042Z

cve-icon NVD

Status : Received

Published: 2025-10-20T17:15:39.367

Modified: 2025-10-20T17:15:39.367

Link: CVE-2025-9574

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.