|
[Japanese]
|
JVNDB-2025-000094
|
Multiple vulnerabilities in ABB Terra AC Wallbox
|
Terra AC Wallbox provided by ABB contains the following vulnerability.
* Heap-based buffer overflow (CWE-122) - CVE-2025-10504
* Classic buffer overflow (CWE-120) - CVE-2025-12142
* Stack-based buffer overflow (CWE-121) - CVE-2025-12143
Ryo Kato of Panasonic reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V3 Severity: Base Metrics 6.1 (Medium) [IPA Score]
- Attack Vector: Adjacent Network
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2025-10504
|
CVSS V3 Severity:
Base Metrics:6.1 (Medium) [IPA Score]
- Attack Vector: Adjacent
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2025-12142
|
CVSS V3 Severity:
Base Metrics:6.1 (Medium) [IPA Score]
- Attack Vector: Adjacent
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2025-12143
|
|
ABB
- Terra AC wallbox (JP) versions 1.8.33 and prior
|
|
* When the affected device processes specially crafted messages sent by an attacker over Bluetooth, it may allow code execution or alteration of firmware behavior (CVE-2025-10504, CVE-2025-12142)
* When the affected device processes specially crafted requests sent by an attacker from OCPP server, it may allow code execution or alteration of firmware behavior (CVE-2025-12143)
|
[Update the firmware]
Update the firmware to the latest version according to the information provided by the developer.
|
ABB
|
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2025-10504
- CVE-2025-12142
- CVE-2025-12143
|
- JVN : JVN#84024274
|
- [2025/12/05]
Web page was published
|