CISA’s advisory for ABB CoreSense HM and CoreSense M10 highlights an important risk in industrial monitoring devices: even vulnerabilities that require local network access can expose sensitive operational data if the device is reachable from poorly segmented environments. The issue, tracked as CVE-2025-3465, is a path traversal vulnerability affecting CoreSense HM through version 2.3.1 and CoreSense M10 through version 1.4.1.12, which could allow access to restricted directories under certain conditions.

Organizations using these transformer monitoring solutions should apply ABB’s recommended updates, including CoreSense HM v2.3.4 and CoreSense M10 v1.4.1.31 or later, and ensure these systems are isolated from enterprise networks with strict access control. OT environments should not rely on “local access required” as a comfort blanket. Once an attacker reaches the control network, even a file path traversal bug can become useful for reconnaissance, data exposure, and follow-on attacks.


View CSAF Summary An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthenticated users to gain access to restricted directories. Exploiting this vulnerability can lead to complete system compromise and exposure of sensitive information. The following versions of ABB CoreSense HM and CoreSense M10 are affected: CoreSense™ HM <=2.3.1, 2.3.4 (CVE-2025-3465) CoreSense™ M10 <=1.4.1.12, 1.4.1.31 (CVE-2025-3465) CVSS Vendor Equipment Vulnerabilities v3 7.1 ABB ABB CoreSense HM and CoreSense M10 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Food and Agriculture, Commercial Facilities, Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-3465 A path traversal vulnerability in these products can allow unauthenticated users to gain access to restricted directories. Exploiting this vulnerability can lead to complete system compromise and exposure of sensitive information. View CVE Details Affected Products ABB CoreSense HM and CoreSense M10 Vendor: ABB Product Version: CoreSense™ HM<=2.3.1, CoreSense™ M10<=1.4.1.12 Product Status: fixed, known_affected Remediations Vendor fix The vulnerabilities are corrected in the following version: CoreSense™ HM v2.3.4 & CoreSense™ M10 v1.4.1.31 ABB recommends that cus

Source: ABB CoreSense HM and CoreSense M10 via CISA Advisories — published 19 May 2026.