VYPR
advisoryPublished Oct 1, 2026· 1 source

CISA Advises on Privilege Escalation and Path Traversal Vulnerabilities in ABB PCM600

CISA has issued an advisory detailing two critical vulnerabilities in ABB's Protection and Control IED Manager PCM600 software, versions 2.14 and earlier, which could allow for privilege escalation and arbitrary file overwrites.

CISA has released an advisory highlighting two significant vulnerabilities affecting ABB's Protection and Control IED Manager PCM600 software, specifically versions 2.14 and prior. These flaws, identified as CVE-2026-15952 and CVE-2026-15953, pose risks of privilege escalation and arbitrary file manipulation on affected systems.

CVE-2026-15952 is rooted in the Scheduler Service component of PCM600. This service operates with elevated privileges under the LocalSystem account, yet it grants standard PCM600 users broad permissions through local group membership. An attacker who has already gained local access and possesses valid user credentials could exploit this misconfiguration to escalate their privileges to that of the LocalSystem account, thereby achieving full control over the host system.

The second vulnerability, CVE-2026-15953, lies within the software's handling of project archive files. Insufficient validation of archive entry paths during the extraction process allows for path traversal. This means an attacker could craft a malicious archive file that, when extracted by PCM600, writes files to arbitrary locations on the file system, potentially overwriting critical system files or injecting malicious content outside of the intended directory.

Successful exploitation of either vulnerability could lead to severe consequences, including unauthorized access, system compromise, and disruption of industrial control operations. The affected software, ABB Protection and Control IED Manager PCM600, is deployed globally within the Energy sector, underscoring the widespread potential impact of these security flaws.

ABB has provided mitigation strategies to reduce the risk associated with these vulnerabilities. One key recommendation is to configure the ABBPCMSchedulerService to run using the same Windows account that is used to operate PCM600. This involves adjusting the service's logon properties via Services.msc to align with the PCM600 application's user account, ensuring the account has the necessary 'Log on as a service' privilege.

Further mitigation advice includes ensuring that when authentication is enabled for the Intelligent Electronic Device (IED), the Scheduler tool is used with the same Windows account configured for the Scheduler Service. Additionally, for installations utilizing IED security certificates, the PCM600 setting 'Always trust IED security certificates' should only be enabled within secure and trusted communication environments.

CISA emphasizes that these vulnerabilities have been assigned CVSS v3.1 base scores of 6.4 (MEDIUM) for CVE-2026-15952 and 5.0 (MEDIUM) for CVE-2026-15953, with CVSS v4.0 scores also provided. While not rated 'CRITICAL', the potential for privilege escalation and arbitrary file writes warrants significant attention from system administrators.

CISA strongly recommends implementing defensive measures to minimize exploitation risks. These include limiting network exposure of control system devices, isolating them behind firewalls, and using secure remote access methods like VPNs. Organizations are urged to perform thorough impact and risk assessments before deploying any defensive measures.

Synthesized by Vypr AI