Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node.
Conclusion & alert: CVE-2022-0902 is rated High Risk (71.2/100): CVSS High severity, with high exploitation likelihood (EPSS 16.36%, 97th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +14.11% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.25% | 16.36% | +14.11% |
| 2 | 2026-01-19 | 6.80% | 2.25% | -4.55% |
| 3 | 2025-11-29 | — | 6.80% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.1 | HIGH |
|
2.2 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| abb | rmc-100_firmware | < 2105457-037 | cpe:2.3:o:abb:rmc-100_firmware:*:*:*:*:*:*:*:* |
| abb | rmc-100-lite_firmware | < 2106229-011 | cpe:2.3:o:abb:rmc-100-lite_firmware:*:*:*:*:*:*:*:* |
| abb | xio_firmware | < 2106198-008 | cpe:2.3:o:abb:xio_firmware:*:*:*:*:*:*:*:* |
| abb | xfcg5_firmware | < 2105805-016 | cpe:2.3:o:abb:xfcg5_firmware:*:*:*:*:*:*:*:* |
| abb | xrcg5_firmware | < 2105864-016 | cpe:2.3:o:abb:xrcg5_firmware:*:*:*:*:*:*:*:* |
| abb | uflog5_firmware | < 2105298-024 | cpe:2.3:o:abb:uflog5_firmware:*:*:*:*:*:*:*:* |
| abb | udc_firmware | < 2106177-007 | cpe:2.3:o:abb:udc_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://search.abb.com/library/Download.aspx?DocumentID=9AKK108467A0927&LanguageCode=en&DocumentPartId=&Action=Launch&_ga | Mitigation Vendor Advisory |