CVE-2025-4677: Idle session timeout is not configured for multiple open ports
Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4677?
CVE-2025-4677 has a severity rating that indicates potential risk due to insufficient session expiration.
How do I fix CVE-2025-4677?
To fix CVE-2025-4677, update the ABB WebPro SNMP Card PowerValue and PowerValue UL firmware to version 1.1.8.L or later.
Which versions are affected by CVE-2025-4677?
CVE-2025-4677 affects ABB WebPro SNMP Card PowerValue and PowerValue UL up to and including version 1.1.8.K.
What are the risks associated with CVE-2025-4677?
The risks associated with CVE-2025-4677 include unauthorized access due to sessions not expiring as intended.
Is there a workaround for CVE-2025-4677?
No official workaround is available for CVE-2025-4677, and upgrading to a secure version is recommended.