CISA + Hersteller
ICS-Advisories
Advisories speziell für industrielle Steuerungssysteme — von CISA ICS-CERT und direkt von Herstellern (Siemens ProductCERT, ABB PSIRT) — einschließlich Revisionshistorie (Erstveröffentlichung, Update A, Update B) und verknüpfter CVEs.
32
Gefunden
Advisory-Daten: Live-Anbindung— zuletzt abgerufen: 24. September 2026 um 06:09.
Filter
1 aktiv32 Advisories gefunden
Veröffentlicht
22. September 2026
Letzte Aktualisierung
22. September 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
A local attacker who successfully exploited this vulnerability could gain elevated privileges by Path Traversal, arbitrarily reading files of system, to cause confidentiality impact of system files.
Zusammenfassung der Gegenmaßnahmen
Mint Workbench I 5876 and the versions before, are impacted, customers who use these products, should: - Disable Service MWI http when it is not in active use. - Restrict physical machine access to authorized personnel only. - Avoid storing sensitive or confidential data on any hosts running service MWI http. - Enable User Account Control (UAC) to block unauthorized privilege escalation attempts. These actions above are the only measures available. No further patch will be released because this product reaches end-of-life globally (out of China) by the end of 2026 and in China by the end of 2027. To exploit the vulnerability the attacker needs to have local access to the machine beforehand and have file write access in the path. Please also refer to section “General security recommendations” for further advise on how to keep your system secure.
Revisionshistorie (1)
Erstveröffentlichung — 22. September 2026
Initial version
Veröffentlicht
18. September 2026
Letzte Aktualisierung
18. September 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An update is available that resolves the reported vulnerability in the product versions under maintenance. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.
Zusammenfassung der Gegenmaßnahmen
Refer to section “General security recommendations” for further advice on how to keep your system secure, as well checking the section “Workarounds”.
Revisionshistorie (1)
Erstveröffentlichung — 18. September 2026
Initial version.
4JDE002044
dynovaPRO™ Reset Credentials Vulnerability
Veröffentlicht
17. September 2026
Letzte Aktualisierung
17. September 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of public reports of a vulnerability in the product listed as affected in the advisory. An update has been deployed to the cloud system that resolves a publicly reported vulnerability in the product versions listed above. An attacker who successfully exploited this vulnerability could take remote control of the product. The vulnerability has been identified in the keycloak authentication component which is integrated into dynovaPRO™. The vulnerability exists in the 'Forgot Password' functionality and allows unauthenticated attackers to bypass authentication and hijack user accounts. Users who have received a password reset mail before the mentioned date, without having requested it, are thereby potentially attacked by exploiting this vulnerability. ABB investigated potentially malicious user reset activities and blocked those user access immediately to reduce the exploitation risk. The credentials of those users have been deleted after the software fix was deployed and the users were informed that they must reset their password to gain access to dynovaPRO™ again.
Zusammenfassung der Gegenmaßnahmen
The following conditions reduce the risk of exploitation of this vulnerability: - Limited Attack Surface: The vulnerability is specific to the password reset functionality. Other authentication methods are not affected. - Email Notifications: Legitimate users receive email notifications during password reset attempts, which may alert them to unauthorized access attempts. Refer to section “General security recommendations” for further advise on how to keep your system secure.
Revisionshistorie (1)
Erstveröffentlichung — 17. September 2026
Initial version
3BHS973333
AC 800PEC, AC 800PEC ARM, AC 800PEC Tool, Control Terminal (xCT) and AC 800PEC Tool Cheetah Impacted by multiple vulnerabilities in Wibu CodeMeter
Veröffentlicht
10. September 2026
Letzte Aktualisierung
10. September 2026
Betroffene Sektoren
Risk Evaluation
An update is available that resolves a publicly reported vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could - Allow arbitrary files to be deleted with system privileges (CVE-2026-81572), - Read potentially sensitive configuration data and overwrite selected values in Server.ini (CVE-2026-81573) - Crash CodeMeter and disclose sensitive information such as process memory and stack canar-ies (CVE-2026-81574) - Crash CodeMeter (CVE-2026-81575), or - Read potentially sensitive license information (CVE-2026-81576)
Zusammenfassung der Gegenmaßnahmen
For CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, and CVE-2026-81576: If you enabled the network server functionality at some point but no longer need it, disable it: - Open the Registry Editor and navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\ WIBUSYSTEMS\CodeMeter\Server\CurrentVersion\, then change the value of IsNetworkServerfrom 1 to 0. - Restart CodeMeter.
Revisionshistorie (1)
Erstveröffentlichung — 10. September 2026
Initial version.
2NGA003144
ABB AbilityTM zenon Security Risk Due to High-Severity Vulnerabilities in WIBU CodeMeter Runtime
Veröffentlicht
9. September 2026
Letzte Aktualisierung
9. September 2026
Betroffene Sektoren
Risk Evaluation
ABB is aware of publicly disclosed security vulnerabilities affecting the WIBU-Systems CodeMeter Runtime for Windows, identified as CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575 and CVE-2026-81576. The CodeMeter Runtime component is used within affected ABB zenon Software Platform installations for software licensing and license server functionality. Successful exploitation of the reported vulnerabilities could enable local privilege escalation on Windows systems and impact systems configured as CodeMeter license servers, potentially leading to unauthorized access, service disruption, or loss of system integrity. Refer to the WIBU-Systems advisory for detailed technical information on each vulnerability. Please see the References section for the WIBU-Systems security advisory.
Zusammenfassung der Gegenmaßnahmen
ABB recommends the following mitigation measures: - Update the WIBU-Systems CodeMeter Runtime to version 8.41a or later. - The latest CodeMeter Runtime software is available from the WIBU-Systems download page: User Software - Wibu-Systems, please see the References section for the corresponding link. - Where upgrading is not feasible, ABB recommends that asset owners perform a risk assessment and implement compensating controls such as network isolation, access restrictions, and enhanced monitoring of affected systems. ABB recommends that customers apply the update at earliest convenience. The vulnerabilities associated with CVE-2026-81573, CVE-2026-81574, CVE-2026-81575 and CVE-2026-81576 are exploitable only when the WIBU-Systems CodeMeter Runtime is configured as a network server, which is not the de-fault configuration. The CVE-2026-81572 vulnerability requires local access to the affected Windows system and execution by a low-privileged user. Consequently, systems with restricted local access, proper privilege management, and limited network exposure are less likely to be successfully compromised. Refer to section “General security recommendations” for further advise on how to keep your system secure.
Revisionshistorie (1)
Erstveröffentlichung — 9. September 2026
Initial version.
3ADR011572
Automation Builder, Drive Application Builder, Virtual Drive, Virtual DrivePlus Impacted by multiple vulnerabilities in Wibu CodeMeter
Veröffentlicht
3. September 2026
Letzte Aktualisierung
3. September 2026
Betroffene Sektoren
Risk Evaluation
An update is available that resolves publicly reported vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could - allow arbitrary files to be deleted with system privileges (CVE-2026-81572), - read potentially sensitive configuration data and overwrite selected values in Server.ini (CVE-2026-81573), - crash CodeMeter and disclose sensitive information such as process memory and stack canaries (CVE-2026-81574), - crash CodeMeter (CVE-2026-81575), or - read potentially sensitive license information (CVE-2026-81576)
Zusammenfassung der Gegenmaßnahmen
For CVE-2026-81572 the exposure can be limited by auditing the list of local users and removing any unnecessary accounts. For CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, and CVE-2026-81576: If you enabled the network server functionality at some point but no longer need it, disable it: - Open the Registry Editor and navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\ WIBUSYSTEMS\CodeMeter\Server\CurrentVersion\, then change the value of IsNetworkServerfrom 1 to 0. - Restart CodeMeter.
Revisionshistorie (1)
Erstveröffentlichung — 3. September 2026
Initial version.
Veröffentlicht
30. Juli 2026
Letzte Aktualisierung
6. August 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits these vulnerabilities could potentially access sensitive information, cause denial of service, or disrupt system availability.
Zusammenfassung der Gegenmaßnahmen
ABB recommends the following mitigation measures: - Replace bundled MongoDB with a supported version if IIoT services are required: - Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. - The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer - Uninstall IIoT Services wherever it’s not required: - If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section “General security recommendations” for further advise on how to keep your system secure.
Revisionshistorie (2)
Erstveröffentlichung — 30. Juli 2026
Initial version
Update A — 6. August 2026
Initial CISA Republication of ABB PSIRT 9AKK108472A9037 advisory
9AKK108472A9037
ABB AbilityTM zenon Security Risk Due to End-of-Life MongoDB Component
Veröffentlicht
30. Juli 2026
Letzte Aktualisierung
30. Juli 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits these vulnerabilities could potentially access sensitive information, cause denial of service, or disrupt system availability.
Zusammenfassung der Gegenmaßnahmen
ABB recommends the following mitigation measures: - Replace bundled MongoDB with a supported version if IIoT services are required: - Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. - The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer - Uninstall IIoT Services wherever it’s not required: - If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section “General security recommendations” for further advise on how to keep your system secure.
Revisionshistorie (1)
Erstveröffentlichung — 30. Juli 2026
Initial version
Veröffentlicht
17. Juli 2026
Letzte Aktualisierung
28. Juli 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures.
Zusammenfassung der Gegenmaßnahmen
Due to the nature of the classic KNX protocol stack and security concept, there are no options to resolve the vulnerability with a software update on a technical level. ABB recommends to follow general security recommendations listed in the security guideline (see References and General security recommendations). In addition, it shall be avoided to control sensitive functionality by legacy KNX devices such as, but not limited to, access control to e.g. hotel rooms or other protected areas. Note: Legacy KNX standards were never designed to meet state of the art security standards like introduced with KNX Data Secure published in 2017.
Revisionshistorie (2)
Erstveröffentlichung — 17. Juli 2026
Initial version
Update A — 28. Juli 2026
Initial CISA Republication of ABB PSIRT 9AKK108472A9270 advisory
9AKK108472A9270
ABB/EL/ELSB/Building Automation File integrity can be bypassed in KNX Update Tool for classic KNX products
Veröffentlicht
17. Juli 2026
Letzte Aktualisierung
17. Juli 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures.
Zusammenfassung der Gegenmaßnahmen
Due to the nature of the classic KNX protocol stack and security concept, there are no options to resolve the vulnerability with a software update on a technical level. ABB recommends to follow general security recommendations listed in the security guideline (see References and General security recommendations). In addition, it shall be avoided to control sensitive functionality by legacy KNX devices such as, but not limited to, access control to e.g. hotel rooms or other protected areas. Note: Legacy KNX standards were never designed to meet state of the art security standards like introduced with KNX Data Secure published in 2017.
Revisionshistorie (1)
Erstveröffentlichung — 17. Juli 2026
Initial version
Veröffentlicht
25. Juni 2026
Letzte Aktualisierung
25. Juni 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system
Zusammenfassung der Gegenmaßnahmen
The problem is corrected in the following product versions: - Edgenius 3.2.4.1 ABB recommends that customers apply the update at earliest convenience.
Revisionshistorie (1)
Erstveröffentlichung — 25. Juni 2026
Initial version.
Veröffentlicht
23. Juni 2026
Letzte Aktualisierung
23. Juni 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.
Zusammenfassung der Gegenmaßnahmen
ABB has investigated the vulnerability and remediated it in the newly released versions. The vulnerability has been resolved in the product versions listed as fixed in the advisory. - Version 6.1.1-2 does not contain this vulnerability and therefore no update is required. The vulnerability was again introduced in 6.1.1-3 when an older ONB version was included in the release media. - Version 6.1.1-4 do not contain this vulnerability but present version 6.1.1-3 by 800xA System Installer and System Configuration Console (SCC). Version 6.1.1-4 is therefore withdrawn. - Version 6.2.0-2 do not contain this vulnerability but present version 6.2.0-1 by 800xA System Installer and System Configuration Console (SCC). Version 6.2.0-2 is therefore withdrawn. ABB recommends that customers apply the update at their earliest convenience. - Control Builder A: It is recommended to update Control Builder A to version 1.4/5 or later. - 800xA for Advant Master: - Versions 6.0.3-1 and earlier, - Versions 6.1.1-1 and earlier, - Versions 6.1.1-2, 6.1.1-3, and 6.1.1-4 should be updated to version 6.1.1-5 or later. - 800xA for Advant Master: - Versions 6.2.0-1 and 6.2.0-2 should be updated to version 6.2.0-3 or later.
Revisionshistorie (1)
Erstveröffentlichung — 23. Juni 2026
Initial version.
Veröffentlicht
10. Juni 2026
Letzte Aktualisierung
17. Juni 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.
Zusammenfassung der Gegenmaßnahmen
ABB recommends using Freelance Extended User Management instead of Security Lock. Freelance Extended User Management is based on Windows user accounts and is available for Freelance 2019 or higher. For Freelance 2016 and earlier, please refer to chapter “General Security Information”. A fix for Freelance Security Lock is in preparation and will be announced in this updated document. Refer to section “General security recommendations” for further advise on how to keep your system secure. To reduce the likelihood of exploitation via keyboard shortcuts: - disable unnecessary accessibility features - use hardened OS configurations that suppress system-level shortcuts - implement BIOS/UEFI-level restrictions on keyboard input during runtime.
Revisionshistorie (2)
Erstveröffentlichung — 10. Juni 2026
Initial version.
Update A — 17. Juni 2026
Correction on the product relationship
Veröffentlicht
3. Juni 2026
Letzte Aktualisierung
3. Juni 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways.
Zusammenfassung der Gegenmaßnahmen
ABB has investigated these vulnerabilities to provide adequate protection to customers. The problem is corrected in the following product versions: T-MAC Plus version 4.0-25 ABB recommends that customers apply the update at earliest convenience.
Revisionshistorie (1)
Erstveröffentlichung — 3. Juni 2026
Initial version.
Veröffentlicht
31. März 2026
Letzte Aktualisierung
22. Mai 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of public reports of vulnerabilities in 7-Zip version 18.5 and Microsoft Azure Data Studio version 1.32 included in the product versions listed as affected in the advisory. The vulnerability in 7-Zip can be exploited if attacker gains control over the system and extracts a malicious file using this version of 7-Zip. Otherwise, the attacker must force the user to visit malicious websites or click links and extract the package through 7-zip. Microsoft Azure Data Studio gets installed along with SQL Server Management Studio. An attacker who successfully exploits vulnerability in Microsoft Azure Data studio may compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. if the Authentication, Authorization and Accountability is not configured properly in the system. However, none of the products listed above uses Microsoft Azure Data Studio. Microsoft Azure Data Studio is automatically removed from the system from System 800xA 7.0 onwards. These vulnerabilities may appear when the product media is scanned. However, they can only be ex-ploited if the vulnerable software is installed on the system. For this reason, it is strongly advised to uninstall outdated or vulnerable versions of third-party software immediately.
Zusammenfassung der Gegenmaßnahmen
Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. There are no workarounds. Uninstalling the affected third-party software fully eliminates the risk of vulnerabilities. Refer to the section ‘Recommended immediate actions’.
Revisionshistorie (2)
Erstveröffentlichung — 31. März 2026
Initial version.
Update A — 22. Mai 2026
Added missing CVE description for CVE-2024-26203.
7PAA020125
Denial of Service Vulnerabilities in System 800xA, Symphony® Plus IEC 61850 communication stack
Veröffentlicht
13. April 2026
Letzte Aktualisierung
13. April 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
This vulnerability was privately reported relating to ABB’s implementation of the IEC 61850 communication stack for MMS client applications used in some Automation control system products. Note: IEC 61850 communication typically supports MMS and GOOSE protocols. Some ABB products support both, others only MMS (e.g. S+ Operations and PM 877). In any case, GOOSE communication is not impacted by this reported vulnerability. If an attacker gains access to a site’s IEC 61850 network, then exploiting this vulnerability will result in a device fault (PM 877, CI850 and CI868 modules) and will require a manual restart. If this attack is directed at a S+ Operations node running IEC 61850 connectivity, this will result in a crash in the IEC 61850 communication driver which, if continued a repeating basis, will also result in a denial-of-service situation. Note that this does not have an impact on the overall availability and functionality of the S+ Operations node, only the IEC 61850 communication function. The System 800xA IEC61850 Connect is not affected.
Zusammenfassung der Gegenmaßnahmen
ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - CI868 (for AC 800M) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in 6.1.1 and 7.0 tracks for 800xA. AC 800M 6.1.1-3 is planned for Q2 2027, AC 800M 7.0 has been released in December 2025. - CI850 (for Symphony Plus SD Series) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version C_0 or later (planned Q2 2026). - PM 877 (Symphony Plus MR) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected with firmware version 3.53 or later (planned Q1 2026). - S+ Operations Versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version 3.4 or later (released in January 2026). ABB recommends customers apply updates, as they become available, at their earliest convenience. It is also advisable to review the Mitigating Factors, Workarounds and General security recommendations sections for additional actions which may help reduce overall risk.
Revisionshistorie (1)
Erstveröffentlichung — 13. April 2026
Initial version.
7PAA017341
PostgreSQL vulnerabilities in ABB Ability™ Symphony® Plus Engineering
Veröffentlicht
13. April 2026
Letzte Aktualisierung
13. April 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB became aware of vulnerability in the products versions listed as affected in the advisory. The ABB S+ Engineering product versions are affected by vulnerabilities in PostgreSQL version 13.11 and earlier versions. If an attacker gains access to a site’s S+ Client Server network, they could exploit such vulnerabilities by executing arbitrary code and potentially compromising the entire system.
Zusammenfassung der Gegenmaßnahmen
ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - Systems using S+ Engineering 2.2 through 2.4 SP2 should upgrade to S+ Engineering 2.4 SP2 RU1 (re-leased in December 2024) or later. - End users who are unable to install one of these updates should immediately look to implement the Mitigation and Workarounds listed below as this will restrict or prevent an attacker’s ability to com-promise the system. ABB recommends that customers apply the update at the earliest convenience.
Revisionshistorie (1)
Erstveröffentlichung — 13. April 2026
Initial version.
4HZM000604
ABB Ability Camera Connect Vulnerabilities in outdated 3rd party component (SQLite 3.2.4)
Veröffentlicht
26. März 2026
Letzte Aktualisierung
26. März 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of public reports of vulnerabilities in a 3rd party dependency SQLite Version 3.2.4 which was delivered together with the installation package of Camera Connect Version 2.0.0.42 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways.
Zusammenfassung der Gegenmaßnahmen
The problem is corrected in the following product versions: - ABB Ability Camera Connect 2.0.0.49. The easiest path to mitigate the problem is an update of ABB Ability Camera Connect system by the customer. ABB recommends that customers apply the update at earliest convenience.
Revisionshistorie (1)
Erstveröffentlichung — 26. März 2026
Initial version.
Veröffentlicht
13. März 2026
Letzte Aktualisierung
13. März 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. AWIN gateways are not intended to be internet-facing. An attacker who successfully exploited this vulnerability could take remote control of the product and reboot the device, potentially causing a denial of service. It can also reveal system specific configuration. ABB requires, as noted in the User Manual, that AWIN gateways should not be exposed to the internet or any other insecure network. Note. To exploit this vulnerability the attacker needs access to the AWIN gateways. These gateways are installed on sites which often have perimeter security, and the gateways are installed behind firewalls.
Zusammenfassung der Gegenmaßnahmen
Do the following actions: - Stop and disconnect any AWIN gateways that are exposed directly to the Internet. - Ensure that physical controls are in place, so no unauthorized personnel can access your devices, components, peripheral equipment, and networks. - Ensure that all AWIN gateways are upgraded to the latest firmware version. Please find the latest version of firmware on the respective product Release Notes. - When remote access is required, only use secure methods. The problem is corrected in the following product versions: - AWIN GW100 rev2: v2.1-0 - AWIN GW120: v2.0-0 ABB recommends that customers contact ABB to obtain the updated firmware as soon as possible. ABB Service Support engineer shall apply the firmware update at earliest convenience.
Revisionshistorie (1)
Erstveröffentlichung — 13. März 2026
Initial version.
Veröffentlicht
12. März 2026
Letzte Aktualisierung
12. März 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability. An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.
Zusammenfassung der Gegenmaßnahmen
The problem is corrected in the following product version: - AC500 V3 firmware version 3.9.0 HF1 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available for download from the ABB library. https://search.abb.com/library/Download.aspx?DocumentID=3ADR011537&LanguageCode=en&DocumentPartId=&Action=Launch
Revisionshistorie (1)
Erstveröffentlichung — 12. März 2026
Initial version.
Veröffentlicht
24. Februar 2026
Letzte Aktualisierung
24. Februar 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. The Windows gateway is accessible remotely by default. Unauthenticated attackers can therefore search for PLCs, but the user management of the PLCs prevents the actual access to the PLCs – unless it is disabled
Zusammenfassung der Gegenmaßnahmen
If remote access is not required, check the "LocalAddress" setting in the [CmpGwCommDrvTcp] section of the Gateway's configuration file as follows (restart of gateway required in case of changes): [CmpGwCommDrvTcp] LocalAddress=127.0.0.1 ; allow access only from the local computer The gateway configuration file can be located at (example for Automation Builder 2.8): %ProgramFiles%\ABB\AB2.8\AutomationBuilder\GatewayPLC\Gateway.cfg Starting with Automation Builder version 2.9.0 the vulnerability is closed by setting the default for the gateway to local access. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download
Revisionshistorie (1)
Erstveröffentlichung — 24. Februar 2026
Initial version.
Veröffentlicht
24. Februar 2026
Letzte Aktualisierung
24. Februar 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. An update is available that resolves these vulnerabilities. An attacker who successfully exploited these vulnerabilities could bypass the user management and read visualization files (CVE-2025-2595), read and write certificates and keys (CVE-2025-41659) or cause a denial-of-service (DoS) (CVE-2025-41691).
Zusammenfassung der Gegenmaßnahmen
The problem is corrected in the following product versions: - AC500 V3 firmware version 3.9.0 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available from Automation Builder 2.9.0. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download
Revisionshistorie (1)
Erstveröffentlichung — 24. Februar 2026
Initial version.
7PAA013309
System 800xA SECURITY Advisory - ABB 800xA Base 6.0.x, 6.1.x CSLib communication DoS vulnerability
Veröffentlicht
5. Juni 2024
Letzte Aktualisierung
23. Januar 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause services to crash and restart by sending specifically crafted messages. The vulnerability only affects 800xA services in PC based client/server nodes. Controllers are not affected by this vulnerability
Zusammenfassung der Gegenmaßnahmen
The problem is corrected in the following product versions: - ABB 800xA Base 6.2.0-0 (part of System 800xA 6.2.0.0) - ABB 800xA Base 6.1.1-3 (part of System 800xA 6.1.1.2) - ABB 800xA Base 6.0.3-10 (RollUp released in September’2025. RollUp requires System 800xA 6.0.3.4 to be installed in the system. See References for more details.) It is recommended to update to an active product version to obtain the latest corrections.
Revisionshistorie (4)
Erstveröffentlichung — 5. Juni 2024
Initial version
Update A — 14. Juni 2024
Included CVSS v4.0 score
Update B — 22. Januar 2025
Updated the planned release date for ABB 800xA Base 6.0.3-x
Update C — 7. Februar 2025
Updated Affected Products and Recommended immediate actions
9AKK108472A1331
ABB Ability™ OPTIMAX® Authentication Bypass in Single-Sign On with Azure Active Directory
Veröffentlicht
16. Januar 2026
Letzte Aktualisierung
16. Januar 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB became aware of severe vulnerability in the products versions listed as affected in the advisory, if the optional integration with Azure Active Directory for Single-Sign On is enabled. We have not received any reports of this vulnerability being exploited. An attacker who successfully exploits this vulnerability could bypass user authentication and potentially cause the product to: - Shutdown the system, - Modify the configuration of the system, - Install and run arbitrary code
Zusammenfassung der Gegenmaßnahmen
The problem is corrected in the following product versions: - ABB Ability OPTIMAX v6.4.1-251120 (see References 9AKK108472A0435) or later - ABB Ability OPTIMAX v6.3.1-251120 (see References 9AKK108472A0437) or later ABB recommends that customers using earlier versions of OPTIMAX v6.4 and OPTIMAX v6.3 apply an update of the operating system at earliest convenience. Customers still using the meanwhile unsupported OPTIMAX v6.2 or v6.1 shall contact ABB to identify the right way forward.
Revisionshistorie (1)
Erstveröffentlichung — 16. Januar 2026
Initial version.
Veröffentlicht
7. Januar 2026
Letzte Aktualisierung
7. Januar 2026
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB became aware of multiple internally discovered vulnerabilities in the WebPro SNMP card PowerValue for the product versions listed as affected in the advisory. Depending upon the vulnerability, an attacker with access to local network who successfully exploited this vulnerability could have - Unauthorized access - Insufficient Session Expiration leading to resource unavailability - Uncontrolled Resource Consumption leading to DOS attack ABB strongly advises customers to update the latest firmware of affected products.
Zusammenfassung der Gegenmaßnahmen
The problem is corrected in the following product versions: WebPro SNMP card PowerValue version 1.1.8.p ABB advises users of the affected product versions to reach out to ABB Digital Service Support (ch.ups.digital@abb.com) for guidance and recommended actions. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information.
Revisionshistorie (1)
Erstveröffentlichung — 7. Januar 2026
Initial version.
4HZM000603
ABB Ability Camera Connect Vulnerabilities in outdated 3rd party component (VLC)
Veröffentlicht
27. November 2025
Letzte Aktualisierung
28. November 2025
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in this advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways.
Zusammenfassung der Gegenmaßnahmen
The VLC-based component operates solely within completely isolated environments without internet access or any connectivity to external networks. Consequently: • No exposure to untrusted MMS streams: The integer overflow vulnerability relies on handling a maliciously crafted external stream, which is not possible in isolated environments • No remote attacker access: Without network ingress, attackers cannot trigger the vulnerability remotely. • Drastically reduced attack surface: The absence of any external media inputs effectively neutralizes the exploit path, significantly lowering the risk of both denial of service and code execution.
Revisionshistorie (2)
Erstveröffentlichung — 27. November 2025
Initial version.
Update A — 28. November 2025
Correction in References
Veröffentlicht
20. November 2025
Letzte Aktualisierung
20. November 2025
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB identified a critical vulnerability present in ABB Ability Edgenius starting from version 3.2.0.0. We have not received any reports of this vulnerability being exploited. An unauthenticated attacker could exploit this vulnerability to: → install and run arbitrary code, → uninstall installed applications, → modify the configuration of installed applications, on systems running the vulnerable versions of ABB Ability Edgenius, including 3.2.0.0 through 3.2.1.1.
Zusammenfassung der Gegenmaßnahmen
ABB has prepared an update to fix this vulnerability included in the latest Roll-Up, ABB Ability Edgenius version 3.2.2.0. ABB advises customers to upgrade as soon as possible. Until the upgrade is applied, ABB advises customers to disable the Edgenius Management Portal to mitigate the vulnerability.
Revisionshistorie (1)
Erstveröffentlichung — 20. November 2025
Initial version.
Veröffentlicht
3. November 2025
Letzte Aktualisierung
3. November 2025
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
An update is available that resolves vulnerability in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could insert and run arbitrary code in the system.
Zusammenfassung der Gegenmaßnahmen
The problem is corrected in the following product version: ABB Protection and control IED manager PCM600 version 2.14. ABB recommends that customers apply the update at earliest convenience. Note: RE_630 protection relays are not compatible with PCM600 version 2.14. When using earlier PCM600 versions with RE_630, the known vulnerability must be mitigated through system-level defenses. For mitigation guidance, refer to the General Security Recommendations.
Revisionshistorie (1)
Erstveröffentlichung — 3. November 2025
Initial version.
4TZ00000006007
ALS-mini-S4/S8 IP Missing Authentication Vulnerability and its Mitigations
Veröffentlicht
20. Oktober 2025
Letzte Aktualisierung
23. Oktober 2025
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.
Zusammenfassung der Gegenmaßnahmen
ABB recommends that customers correctly configure the device in the network by referring to section Mitigating factors, or apply Workarounds to completely eliminate the attack vector.
Revisionshistorie (2)
Erstveröffentlichung — 20. Oktober 2025
Initial version.
Update A — 23. Oktober 2025
Updated CVSS 3.1 score
9AKK108471A8948
Terra AC wallbox Heap Memory Corruption Vulnerability
Veröffentlicht
20. Oktober 2025
Letzte Aktualisierung
21. Oktober 2025
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.
Zusammenfassung der Gegenmaßnahmen
The problem is corrected in the product versions listed as fixed in the advisory. Terra AC wallbox (UL40/80A) 1.8.33 Terra AC wallbox (UL32A) 1.8.34 Terra AC MID 1.8.34 Terra AC Juno CE 1.8.34 Terra AC PTB 1.8.33 Terra AC wallbox (JP) 1.8.34 Additionally, we strongly recommend not use unsafe mode(http) to connect your charger to your backend even though OCPP is allowed to do in this way, which absolutely could be attacked by malicious man or organization as a common knowledge. ABB recommends that customers apply the update at earliest convenience.
Revisionshistorie (2)
Erstveröffentlichung — 20. Oktober 2025
Initial version.
Update A — 21. Oktober 2025
Final version
3KXG200000R4801
CoreSense™ HM and CoreSense™ M10 File Path Traversal Vulnerability
Veröffentlicht
16. April 2025
Letzte Aktualisierung
20. Oktober 2025
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthenticated users to gain access to restricted directories. Exploiting this vulnerability can lead to complete system compromise and exposure of sensitive information.
Zusammenfassung der Gegenmaßnahmen
The vulnerabilities are corrected in the following version: CoreSense™ HM v2.3.4 & CoreSense™ M10 v1.4.1.31 ABB recommends that customers apply the update at the earliest convenience.
Revisionshistorie (4)
Erstveröffentlichung — 16. April 2025
Initial version.
Update A — 30. September 2025
Addressed comments.
Update B — 7. Oktober 2025
Fixed incorrect links.
Update C — 20. Oktober 2025
Final version with corrected dates.
Veröffentlicht
8. Oktober 2025
Letzte Aktualisierung
8. Oktober 2025
Verknüpfte CVEs
Betroffene Sektoren
Risk Evaluation
ABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits vulnerability could have access to application’s sensitive information. ABB strongly advises customers to update MConfig with latest software version.
Zusammenfassung der Gegenmaßnahmen
The vulnerability is resolved in the following product versions: MConfig version 1.4.9.22 ABB advises users to update their devices to the latest software version. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information
Revisionshistorie (1)
Erstveröffentlichung — 8. Oktober 2025
Initial version.