ABB EIBPORT
CISA says ABB EIBPORT has a high-severity XSS flaw that can expose session IDs and let an attacker change device settings. ABB says a firmware update fixes the issue.
Intelligence analysis by GPT-5.4 Mini
CISA issued an advisory for ABB EIBPORT covering a high-severity web vulnerability tied to insecure session handling and cross-site scripting. The flaw affects several EIBPORT V3 KNX variants below firmware 3.9.2 and could let an attacker access sensitive data or alter configuration.
A company found a weakness in a building-control device called EIBPORT. The problem could let the wrong person sneak in, see private information, or change settings.
It is a bit like a smart lock that sometimes trusts the wrong keycard. If someone gets the special pass token, they may act like they belong there.
ABB says a firmware update fixes it. CISA also says these systems should stay away from the open internet, like keeping a house key inside the house instead of leaving it on the front porch.
Analysis
What CISA says
CISA’s advisory says ABB is aware of vulnerabilities in affected versions of EIBPORT and that a firmware update is available. The core risk is that a successful attacker could access sensitive information stored on the device and change its configuration.
What is affected
The advisory lists three affected product lines: EIBPORT V3 KNX (2CLA963710W1001), EIBPORT V3 KNX (2CSM256242R2001), and EIBPORT V3 KNX GSM (2CLA963720W1001), all below version 3.9.2. CISA rates the issue as CVSS 3.1 base score 8.0, High, and maps it to CWE-79, improper neutralization of input during web page generation.
What the flaw does
The FAQ says the session management of vulnerable firmware fails to maintain secure session handling. The vulnerable behavior allows a successful attacker to receive a copy of the session ID, and ABB says the update changes how firmware verifies login credentials and token or session identifiers. The result is that an attacker may gain access to the device without authenticating.
Exposure and mitigation
CISA repeats standard industrial-control guidance: keep process control systems physically protected, avoid direct internet exposure, and separate them from other networks with tightly controlled firewalls. ABB says this should not be exploitable remotely when deployed according to best practices, but also notes some customers have exposed devices to the internet or other untrusted networks, which ABB says is against intended use. ABB credits Psytester with reporting the vulnerability.
Key points
- CISA says ABB EIBPORT has a high-severity vulnerability in affected firmware versions below 3.9.2.
- The flaw involves cross-site scripting and weak session management that could expose a session ID.
- An attacker could access sensitive data and change the device configuration if exploitation succeeds.
- ABB says a firmware update is available and recommends applying it as soon as possible.
- CISA emphasizes network segmentation and avoiding direct internet exposure for control systems.



