The vendor explicitly identifies these products as affected by this CVE.
- All ABB Automation Builder <= 2.8.0
- Summary
- Automation Builder projects including AC500 V2 or SM560-S devices contain the application files for these devices. An attacker could try to modify parts of these files so that the project can be changed by overruling the Automation Builder user management.
- Remediation
- Immediate workarounds to close the vulnerability: • CVE-2025-3395: In the project settings, set “Security” to “Encryption” ABB recommends that customers apply the workarounds at earliest convenience. With the next Automation Builder version 2.8.1, the default for “Security” will be set to “Integrity check”. The release of Automation Builder version 2.8.1 is scheduled for July 2025.
