โ† Back to Feed

ABB Protection and Control IED Manager PCM600

CVE-2026-15952CVE-2026-15953

October 1, 2026 ยท CISA (US-CERT) ยท Severity: CRITICAL

This advisory covers two vulnerabilities in ABB's PCM600 software used for protection and control IED management. Successful exploitation could allow an attacker to escalate privileges or overwrite files. The vulnerabilities stem from incorrect permission assignment for critical resources and improper limitation of a pathname to a restricted directory. ๐Ÿ“Œ **Analyst Note:** While the CVSS score is moderate, the ability to escalate to LocalSystem in an energy sector environment is significant, as it could lead to full host compromise. Organizations should apply the recommended workaround and consider updating to a patched version when available.

Key Takeaways

  • ABB's Protection and Control IED Manager PCM600 contains vulnerabilities that allow an attacker with local access and valid credentials to escalate privileges to the LocalSystem account due to incorrect permission assignments.
  • The vulnerabilities also include a path traversal flaw that could enable file overwriting, affecting all PCM600 versions up to and including 2.14, with a CVSS score of 6.4.
  • ABB recommends a workaround that involves configuring the ABBPCMSchedulerService to run under the same Windows account used to operate PCM600, which reduces the risk of privilege escalation.
โ˜• Buy a Coffee