Direkt zum Inhalt
IACS RadarIndustrial Cyber Exposure & Intelligence

CISA + Hersteller

ICS-Advisories

Advisories speziell für industrielle Steuerungssysteme — von CISA ICS-CERT und direkt von Herstellern (Siemens ProductCERT, ABB PSIRT) — einschließlich Revisionshistorie (Erstveröffentlichung, Update A, Update B) und verknüpfter CVEs.

32

Gefunden

Advisory-Daten: Live-Anbindung— zuletzt abgerufen: 24. September 2026 um 06:09.

32 Advisories gefunden

9AKK108473A3188

Mint Workbench I Path traversal Vulnerability

ABBMint Workbench I

ABB PSIRThoch

Veröffentlicht

22. September 2026

Letzte Aktualisierung

22. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

A local attacker who successfully exploited this vulnerability could gain elevated privileges by Path Traversal, arbitrarily reading files of system, to cause confidentiality impact of system files.

Zusammenfassung der Gegenmaßnahmen

Mint Workbench I 5876 and the versions before, are impacted, customers who use these products, should: - Disable Service MWI http when it is not in active use. - Restrict physical machine access to authorized personnel only. - Avoid storing sensitive or confidential data on any hosts running service MWI http. - Enable User Account Control (UAC) to block unauthorized privilege escalation attempts. These actions above are the only measures available. No further patch will be released because this product reaches end-of-life globally (out of China) by the end of 2026 and in China by the end of 2027. To exploit the vulnerability the attacker needs to have local access to the machine beforehand and have file write access in the path. Please also refer to section “General security recommendations” for further advise on how to keep your system secure.

Revisionshistorie (1)
  1. Erstveröffentlichung22. September 2026

    Initial version

Offizielle Quelle: ABB PSIRT

7PAA010706

Freelance Missing Length Check

ABBSystem Version

ABB PSIRThoch

Veröffentlicht

18. September 2026

Letzte Aktualisierung

18. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An update is available that resolves the reported vulnerability in the product versions under maintenance. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.

Zusammenfassung der Gegenmaßnahmen

Refer to section “General security recommendations” for further advice on how to keep your system secure, as well checking the section “Workarounds”.

Revisionshistorie (1)
  1. Erstveröffentlichung18. September 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

4JDE002044

dynovaPRO™ Reset Credentials Vulnerability

ABBdynovaPRO™ cloud system < 2026-08-27 12:00 (CEST)

ABB PSIRTkritisch

Veröffentlicht

17. September 2026

Letzte Aktualisierung

17. September 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB is aware of public reports of a vulnerability in the product listed as affected in the advisory. An update has been deployed to the cloud system that resolves a publicly reported vulnerability in the product versions listed above. An attacker who successfully exploited this vulnerability could take remote control of the product. The vulnerability has been identified in the keycloak authentication component which is integrated into dynovaPRO™. The vulnerability exists in the 'Forgot Password' functionality and allows unauthenticated attackers to bypass authentication and hijack user accounts. Users who have received a password reset mail before the mentioned date, without having requested it, are thereby potentially attacked by exploiting this vulnerability. ABB investigated potentially malicious user reset activities and blocked those user access immediately to reduce the exploitation risk. The credentials of those users have been deleted after the software fix was deployed and the users were informed that they must reset their password to gain access to dynovaPRO™ again.

Zusammenfassung der Gegenmaßnahmen

The following conditions reduce the risk of exploitation of this vulnerability: - Limited Attack Surface: The vulnerability is specific to the password reset functionality. Other authentication methods are not affected. - Email Notifications: Legitimate users receive email notifications during password reset attempts, which may alert them to unauthorized access attempts. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revisionshistorie (1)
  1. Erstveröffentlichung17. September 2026

    Initial version

Offizielle Quelle: ABB PSIRT

3BHS973333

AC 800PEC, AC 800PEC ARM, AC 800PEC Tool, Control Terminal (xCT) and AC 800PEC Tool Cheetah Impacted by multiple vulnerabilities in Wibu CodeMeter

ABBAC 800PEC

ABB PSIRThoch

Veröffentlicht

10. September 2026

Letzte Aktualisierung

10. September 2026

Betroffene Sektoren

Risk Evaluation

An update is available that resolves a publicly reported vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could - Allow arbitrary files to be deleted with system privileges (CVE-2026-81572), - Read potentially sensitive configuration data and overwrite selected values in Server.ini (CVE-2026-81573) - Crash CodeMeter and disclose sensitive information such as process memory and stack canar-ies (CVE-2026-81574) - Crash CodeMeter (CVE-2026-81575), or - Read potentially sensitive license information (CVE-2026-81576)

Zusammenfassung der Gegenmaßnahmen

For CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, and CVE-2026-81576: If you enabled the network server functionality at some point but no longer need it, disable it: - Open the Registry Editor and navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\ WIBUSYSTEMS\CodeMeter\Server\CurrentVersion\, then change the value of IsNetworkServerfrom 1 to 0. - Restart CodeMeter.

Revisionshistorie (1)
  1. Erstveröffentlichung10. September 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

2NGA003144

ABB AbilityTM zenon Security Risk Due to High-Severity Vulnerabilities in WIBU CodeMeter Runtime

ABBAbilityTM zenon

ABB PSIRThoch

Veröffentlicht

9. September 2026

Letzte Aktualisierung

9. September 2026

Betroffene Sektoren

Risk Evaluation

ABB is aware of publicly disclosed security vulnerabilities affecting the WIBU-Systems CodeMeter Runtime for Windows, identified as CVE-2026-81572, CVE-2026-81573, CVE-2026-81574, CVE-2026-81575 and CVE-2026-81576. The CodeMeter Runtime component is used within affected ABB zenon Software Platform installations for software licensing and license server functionality. Successful exploitation of the reported vulnerabilities could enable local privilege escalation on Windows systems and impact systems configured as CodeMeter license servers, potentially leading to unauthorized access, service disruption, or loss of system integrity. Refer to the WIBU-Systems advisory for detailed technical information on each vulnerability. Please see the References section for the WIBU-Systems security advisory.

Zusammenfassung der Gegenmaßnahmen

ABB recommends the following mitigation measures: - Update the WIBU-Systems CodeMeter Runtime to version 8.41a or later. - The latest CodeMeter Runtime software is available from the WIBU-Systems download page: User Software - Wibu-Systems, please see the References section for the corresponding link. - Where upgrading is not feasible, ABB recommends that asset owners perform a risk assessment and implement compensating controls such as network isolation, access restrictions, and enhanced monitoring of affected systems. ABB recommends that customers apply the update at earliest convenience. The vulnerabilities associated with CVE-2026-81573, CVE-2026-81574, CVE-2026-81575 and CVE-2026-81576 are exploitable only when the WIBU-Systems CodeMeter Runtime is configured as a network server, which is not the de-fault configuration. The CVE-2026-81572 vulnerability requires local access to the affected Windows system and execution by a low-privileged user. Consequently, systems with restricted local access, proper privilege management, and limited network exposure are less likely to be successfully compromised. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revisionshistorie (1)
  1. Erstveröffentlichung9. September 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

3ADR011572

Automation Builder, Drive Application Builder, Virtual Drive, Virtual DrivePlus Impacted by multiple vulnerabilities in Wibu CodeMeter

ABBAutomation Builder

ABB PSIRThoch

Veröffentlicht

3. September 2026

Letzte Aktualisierung

3. September 2026

Betroffene Sektoren

Risk Evaluation

An update is available that resolves publicly reported vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could - allow arbitrary files to be deleted with system privileges (CVE-2026-81572), - read potentially sensitive configuration data and overwrite selected values in Server.ini (CVE-2026-81573), - crash CodeMeter and disclose sensitive information such as process memory and stack canaries (CVE-2026-81574), - crash CodeMeter (CVE-2026-81575), or - read potentially sensitive license information (CVE-2026-81576)

Zusammenfassung der Gegenmaßnahmen

For CVE-2026-81572 the exposure can be limited by auditing the list of local users and removing any unnecessary accounts. For CVE-2026-81573, CVE-2026-81574, CVE-2026-81575, and CVE-2026-81576: If you enabled the network server functionality at some point but no longer need it, disable it: - Open the Registry Editor and navigate to Computer\HKEY_LOCAL_MACHINE\SOFTWARE\ WIBUSYSTEMS\CodeMeter\Server\CurrentVersion\, then change the value of IsNetworkServerfrom 1 to 0. - Restart CodeMeter.

Revisionshistorie (1)
  1. Erstveröffentlichung3. September 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

ICSA-26-218-01

ABB Ability Zenon

ABBAbility Zenon

CISAhoch

Risk Evaluation

ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits these vulnerabilities could potentially access sensitive information, cause denial of service, or disrupt system availability.

Zusammenfassung der Gegenmaßnahmen

ABB recommends the following mitigation measures: - Replace bundled MongoDB with a supported version if IIoT services are required: - Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. - The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer - Uninstall IIoT Services wherever it’s not required: - If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revisionshistorie (2)
  1. Erstveröffentlichung30. Juli 2026

    Initial version

  2. Update A6. August 2026

    Initial CISA Republication of ABB PSIRT 9AKK108472A9037 advisory

Offizielle Quelle: CISA

9AKK108472A9037

ABB AbilityTM zenon Security Risk Due to End-of-Life MongoDB Component

ABBAbility Zenon

ABB PSIRThoch

Risk Evaluation

ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits these vulnerabilities could potentially access sensitive information, cause denial of service, or disrupt system availability.

Zusammenfassung der Gegenmaßnahmen

ABB recommends the following mitigation measures: - Replace bundled MongoDB with a supported version if IIoT services are required: - Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. - The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer - Uninstall IIoT Services wherever it’s not required: - If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section “General security recommendations” for further advise on how to keep your system secure.

Revisionshistorie (1)
  1. Erstveröffentlichung30. Juli 2026

    Initial version

Offizielle Quelle: ABB PSIRT

ICSA-26-209-07

ABB KNX Update Tool

ABBKNX Update Tool (ABB)

CISAmiddel

Veröffentlicht

17. Juli 2026

Letzte Aktualisierung

28. Juli 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures.

Zusammenfassung der Gegenmaßnahmen

Due to the nature of the classic KNX protocol stack and security concept, there are no options to resolve the vulnerability with a software update on a technical level. ABB recommends to follow general security recommendations listed in the security guideline (see References and General security recommendations). In addition, it shall be avoided to control sensitive functionality by legacy KNX devices such as, but not limited to, access control to e.g. hotel rooms or other protected areas. Note: Legacy KNX standards were never designed to meet state of the art security standards like introduced with KNX Data Secure published in 2017.

Revisionshistorie (2)
  1. Erstveröffentlichung17. Juli 2026

    Initial version

  2. Update A28. Juli 2026

    Initial CISA Republication of ABB PSIRT 9AKK108472A9270 advisory

Offizielle Quelle: CISA

9AKK108472A9270

ABB/EL/ELSB/Building Automation File integrity can be bypassed in KNX Update Tool for classic KNX products

ABBKNX Update Tool (ABB)

ABB PSIRTmiddel

Veröffentlicht

17. Juli 2026

Letzte Aktualisierung

17. Juli 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures.

Zusammenfassung der Gegenmaßnahmen

Due to the nature of the classic KNX protocol stack and security concept, there are no options to resolve the vulnerability with a software update on a technical level. ABB recommends to follow general security recommendations listed in the security guideline (see References and General security recommendations). In addition, it shall be avoided to control sensitive functionality by legacy KNX devices such as, but not limited to, access control to e.g. hotel rooms or other protected areas. Note: Legacy KNX standards were never designed to meet state of the art security standards like introduced with KNX Data Secure published in 2017.

Revisionshistorie (1)
  1. Erstveröffentlichung17. Juli 2026

    Initial version

Offizielle Quelle: ABB PSIRT

7PAA024620

ABB Ability Edgenius: Copy Fail

ABBUnbekanntes Produkt

ABB PSIRThoch

Veröffentlicht

25. Juni 2026

Letzte Aktualisierung

25. Juni 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete control of the system

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: - Edgenius 3.2.4.1 ABB recommends that customers apply the update at earliest convenience.

Revisionshistorie (1)
  1. Erstveröffentlichung25. Juni 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

7PAA020047

Advant Master Online Builder DLL vulnerability

ABBControl Builder A

ABB PSIRTmiddel

Veröffentlicht

23. Juni 2026

Letzte Aktualisierung

23. Juni 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory, where an incorrect version of Online Builder (ONB) was included in the media. An update is available that resolves the vulnerability, see details in Recommended immediate actions.

Zusammenfassung der Gegenmaßnahmen

ABB has investigated the vulnerability and remediated it in the newly released versions. The vulnerability has been resolved in the product versions listed as fixed in the advisory. - Version 6.1.1-2 does not contain this vulnerability and therefore no update is required. The vulnerability was again introduced in 6.1.1-3 when an older ONB version was included in the release media. - Version 6.1.1-4 do not contain this vulnerability but present version 6.1.1-3 by 800xA System Installer and System Configuration Console (SCC). Version 6.1.1-4 is therefore withdrawn. - Version 6.2.0-2 do not contain this vulnerability but present version 6.2.0-1 by 800xA System Installer and System Configuration Console (SCC). Version 6.2.0-2 is therefore withdrawn. ABB recommends that customers apply the update at their earliest convenience. - Control Builder A: It is recommended to update Control Builder A to version 1.4/5 or later. - 800xA for Advant Master: - Versions 6.0.3-1 and earlier, - Versions 6.1.1-1 and earlier, - Versions 6.1.1-2, 6.1.1-3, and 6.1.1-4 should be updated to version 6.1.1-5 or later. - 800xA for Advant Master: - Versions 6.2.0-1 and 6.2.0-2 should be updated to version 6.2.0-3 or later.

Revisionshistorie (1)
  1. Erstveröffentlichung23. Juni 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

7PAA020361

Freelance Security Lock - Access to Windows OS

ABBSystem Version

ABB PSIRTmiddel

Veröffentlicht

10. Juni 2026

Letzte Aktualisierung

17. Juni 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the product to stop or make the product inaccessible.

Zusammenfassung der Gegenmaßnahmen

ABB recommends using Freelance Extended User Management instead of Security Lock. Freelance Extended User Management is based on Windows user accounts and is available for Freelance 2019 or higher. For Freelance 2016 and earlier, please refer to chapter “General Security Information”. A fix for Freelance Security Lock is in preparation and will be announced in this updated document. Refer to section “General security recommendations” for further advise on how to keep your system secure. To reduce the likelihood of exploitation via keyboard shortcuts: - disable unnecessary accessibility features - use hardened OS configurations that suppress system-level shortcuts - implement BIOS/UEFI-level restrictions on keyboard input during runtime.

Revisionshistorie (2)
  1. Erstveröffentlichung10. Juni 2026

    Initial version.

  2. Update A17. Juni 2026

    Correction on the product relationship

Offizielle Quelle: ABB PSIRT

9AKK108472A7840

Vulnerabilities in T-MAC Plus

ABBT-MAC Plus

ABB PSIRTkritisch

Veröffentlicht

3. Juni 2026

Letzte Aktualisierung

3. Juni 2026

Betroffene Sektoren

Risk Evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways.

Zusammenfassung der Gegenmaßnahmen

ABB has investigated these vulnerabilities to provide adequate protection to customers. The problem is corrected in the following product versions: T-MAC Plus version 4.0-25 ABB recommends that customers apply the update at earliest convenience.

Revisionshistorie (1)
  1. Erstveröffentlichung3. Juni 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

7PAA023732

System 800xA affected by 3rd party component vulnerabilities

ABB800xA History

ABB PSIRThoch

Risk Evaluation

ABB is aware of public reports of vulnerabilities in 7-Zip version 18.5 and Microsoft Azure Data Studio version 1.32 included in the product versions listed as affected in the advisory. The vulnerability in 7-Zip can be exploited if attacker gains control over the system and extracts a malicious file using this version of 7-Zip. Otherwise, the attacker must force the user to visit malicious websites or click links and extract the package through 7-zip. Microsoft Azure Data Studio gets installed along with SQL Server Management Studio. An attacker who successfully exploits vulnerability in Microsoft Azure Data studio may compromise the security of the product by gaining privileges, reading sensitive information, executing commands, evading detection, etc. if the Authentication, Authorization and Accountability is not configured properly in the system. However, none of the products listed above uses Microsoft Azure Data Studio. Microsoft Azure Data Studio is automatically removed from the system from System 800xA 7.0 onwards. These vulnerabilities may appear when the product media is scanned. However, they can only be ex-ploited if the vulnerable software is installed on the system. For this reason, it is strongly advised to uninstall outdated or vulnerable versions of third-party software immediately.

Zusammenfassung der Gegenmaßnahmen

Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. There are no workarounds. Uninstalling the affected third-party software fully eliminates the risk of vulnerabilities. Refer to the section ‘Recommended immediate actions’.

Revisionshistorie (2)
  1. Erstveröffentlichung31. März 2026

    Initial version.

  2. Update A22. Mai 2026

    Added missing CVE description for CVE-2024-26203.

Offizielle Quelle: ABB PSIRT

7PAA020125

Denial of Service Vulnerabilities in System 800xA, Symphony® Plus IEC 61850 communication stack

ABBS+ Operations

ABB PSIRTmiddel

Veröffentlicht

13. April 2026

Letzte Aktualisierung

13. April 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

This vulnerability was privately reported relating to ABB’s implementation of the IEC 61850 communication stack for MMS client applications used in some Automation control system products. Note: IEC 61850 communication typically supports MMS and GOOSE protocols. Some ABB products support both, others only MMS (e.g. S+ Operations and PM 877). In any case, GOOSE communication is not impacted by this reported vulnerability. If an attacker gains access to a site’s IEC 61850 network, then exploiting this vulnerability will result in a device fault (PM 877, CI850 and CI868 modules) and will require a manual restart. If this attack is directed at a S+ Operations node running IEC 61850 connectivity, this will result in a crash in the IEC 61850 communication driver which, if continued a repeating basis, will also result in a denial-of-service situation. Note that this does not have an impact on the overall availability and functionality of the S+ Operations node, only the IEC 61850 communication function. The System 800xA IEC61850 Connect is not affected.

Zusammenfassung der Gegenmaßnahmen

ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - CI868 (for AC 800M) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in 6.1.1 and 7.0 tracks for 800xA. AC 800M 6.1.1-3 is planned for Q2 2027, AC 800M 7.0 has been released in December 2025. - CI850 (for Symphony Plus SD Series) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version C_0 or later (planned Q2 2026). - PM 877 (Symphony Plus MR) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected with firmware version 3.53 or later (planned Q1 2026). - S+ Operations Versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version 3.4 or later (released in January 2026). ABB recommends customers apply updates, as they become available, at their earliest convenience. It is also advisable to review the Mitigating Factors, Workarounds and General security recommendations sections for additional actions which may help reduce overall risk.

Revisionshistorie (1)
  1. Erstveröffentlichung13. April 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

7PAA017341

PostgreSQL vulnerabilities in ABB Ability™ Symphony® Plus Engineering

ABBUnbekanntes Produkt

ABB PSIRThoch

Veröffentlicht

13. April 2026

Letzte Aktualisierung

13. April 2026

Betroffene Sektoren

Risk Evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. The ABB S+ Engineering product versions are affected by vulnerabilities in PostgreSQL version 13.11 and earlier versions. If an attacker gains access to a site’s S+ Client Server network, they could exploit such vulnerabilities by executing arbitrary code and potentially compromising the entire system.

Zusammenfassung der Gegenmaßnahmen

ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - Systems using S+ Engineering 2.2 through 2.4 SP2 should upgrade to S+ Engineering 2.4 SP2 RU1 (re-leased in December 2024) or later. - End users who are unable to install one of these updates should immediately look to implement the Mitigation and Workarounds listed below as this will restrict or prevent an attacker’s ability to com-promise the system. ABB recommends that customers apply the update at the earliest convenience.

Revisionshistorie (1)
  1. Erstveröffentlichung13. April 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

4HZM000604

ABB Ability Camera Connect Vulnerabilities in outdated 3rd party component (SQLite 3.2.4)

ABBAbility Camera Connect

ABB PSIRTkritisch

Risk Evaluation

ABB is aware of public reports of vulnerabilities in a 3rd party dependency SQLite Version 3.2.4 which was delivered together with the installation package of Camera Connect Version 2.0.0.42 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: - ABB Ability Camera Connect 2.0.0.49. The easiest path to mitigate the problem is an update of ABB Ability Camera Connect system by the customer. ABB recommends that customers apply the update at earliest convenience.

Revisionshistorie (1)
  1. Erstveröffentlichung26. März 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

4JNO000329

AWIN Gateways Vulnerabilities in Embedded Webserver

ABBAWIN Firmware

ABB PSIRThoch

Veröffentlicht

13. März 2026

Letzte Aktualisierung

13. März 2026

Betroffene Sektoren

Risk Evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. AWIN gateways are not intended to be internet-facing. An attacker who successfully exploited this vulnerability could take remote control of the product and reboot the device, potentially causing a denial of service. It can also reveal system specific configuration. ABB requires, as noted in the User Manual, that AWIN gateways should not be exposed to the internet or any other insecure network. Note. To exploit this vulnerability the attacker needs access to the AWIN gateways. These gateways are installed on sites which often have perimeter security, and the gateways are installed behind firewalls.

Zusammenfassung der Gegenmaßnahmen

Do the following actions: - Stop and disconnect any AWIN gateways that are exposed directly to the Internet. - Ensure that physical controls are in place, so no unauthorized personnel can access your devices, components, peripheral equipment, and networks. - Ensure that all AWIN gateways are upgraded to the latest firmware version. Please find the latest version of firmware on the respective product Release Notes. - When remote access is required, only use secure methods. The problem is corrected in the following product versions: - AWIN GW100 rev2: v2.1-0 - AWIN GW120: v2.0-0 ABB recommends that customers contact ABB to obtain the updated firmware as soon as possible. ABB Service Support engineer shall apply the firmware update at earliest convenience.

Revisionshistorie (1)
  1. Erstveröffentlichung13. März 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

3ADR011536

AC500 V3 Stack buffer overflow in Cryptographic Message Syntax

ABBAC500 V3 Firmware

ABB PSIRTkritisch

Veröffentlicht

12. März 2026

Letzte Aktualisierung

12. März 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability. An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product version: - AC500 V3 firmware version 3.9.0 HF1 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available for download from the ABB library. https://search.abb.com/library/Download.aspx?DocumentID=3ADR011537&LanguageCode=en&DocumentPartId=&Action=Launch

Revisionshistorie (1)
  1. Erstveröffentlichung12. März 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

3ADR011525

ABB Automation Builder Gateway for Windows with insecure defaults

ABBAutomation Builder

ABB PSIRTmiddel

Veröffentlicht

24. Februar 2026

Letzte Aktualisierung

24. Februar 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. The Windows gateway is accessible remotely by default. Unauthenticated attackers can therefore search for PLCs, but the user management of the PLCs prevents the actual access to the PLCs – unless it is disabled

Zusammenfassung der Gegenmaßnahmen

If remote access is not required, check the "LocalAddress" setting in the [CmpGwCommDrvTcp] section of the Gateway's configuration file as follows (restart of gateway required in case of changes): [CmpGwCommDrvTcp] LocalAddress=127.0.0.1 ; allow access only from the local computer The gateway configuration file can be located at (example for Automation Builder 2.8): %ProgramFiles%\ABB\AB2.8\AutomationBuilder\GatewayPLC\Gateway.cfg Starting with Automation Builder version 2.9.0 the vulnerability is closed by setting the default for the gateway to local access. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download

Revisionshistorie (1)
  1. Erstveröffentlichung24. Februar 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

3ADR011524

AC500 V3 Multiple vulnerabilities

ABBAC500 V3

ABB PSIRThoch

Veröffentlicht

24. Februar 2026

Letzte Aktualisierung

24. Februar 2026

Betroffene Sektoren

Risk Evaluation

ABB became aware of severe vulnerability in the products versions listed as affected in the advisory. An update is available that resolves these vulnerabilities. An attacker who successfully exploited these vulnerabilities could bypass the user management and read visualization files (CVE-2025-2595), read and write certificates and keys (CVE-2025-41659) or cause a denial-of-service (DoS) (CVE-2025-41691).

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: - AC500 V3 firmware version 3.9.0 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available from Automation Builder 2.9.0. Automation Builder 2.9.0 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download

Revisionshistorie (1)
  1. Erstveröffentlichung24. Februar 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

7PAA013309

System 800xA SECURITY Advisory - ABB 800xA Base 6.0.x, 6.1.x CSLib communication DoS vulnerability

ABB800xA Base

ABB PSIRTmiddel

Veröffentlicht

5. Juni 2024

Letzte Aktualisierung

23. Januar 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB is aware of a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause services to crash and restart by sending specifically crafted messages. The vulnerability only affects 800xA services in PC based client/server nodes. Controllers are not affected by this vulnerability

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: - ABB 800xA Base 6.2.0-0 (part of System 800xA 6.2.0.0) - ABB 800xA Base 6.1.1-3 (part of System 800xA 6.1.1.2) - ABB 800xA Base 6.0.3-10 (RollUp released in September’2025. RollUp requires System 800xA 6.0.3.4 to be installed in the system. See References for more details.) It is recommended to update to an active product version to obtain the latest corrections.

Revisionshistorie (4)
  1. Erstveröffentlichung5. Juni 2024

    Initial version

  2. Update A14. Juni 2024

    Included CVSS v4.0 score

  3. Update B22. Januar 2025

    Updated the planned release date for ABB 800xA Base 6.0.3-x

  4. Update C7. Februar 2025

    Updated Affected Products and Recommended immediate actions

Offizielle Quelle: ABB PSIRT

9AKK108472A1331

ABB Ability™ OPTIMAX® Authentication Bypass in Single-Sign On with Azure Active Directory

ABBUnbekanntes Produkt

ABB PSIRThoch

Veröffentlicht

16. Januar 2026

Letzte Aktualisierung

16. Januar 2026

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB became aware of severe vulnerability in the products versions listed as affected in the advisory, if the optional integration with Azure Active Directory for Single-Sign On is enabled. We have not received any reports of this vulnerability being exploited. An attacker who successfully exploits this vulnerability could bypass user authentication and potentially cause the product to: - Shutdown the system, - Modify the configuration of the system, - Install and run arbitrary code

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: - ABB Ability OPTIMAX v6.4.1-251120 (see References 9AKK108472A0435) or later - ABB Ability OPTIMAX v6.3.1-251120 (see References 9AKK108472A0437) or later ABB recommends that customers using earlier versions of OPTIMAX v6.4 and OPTIMAX v6.3 apply an update of the operating system at earliest convenience. Customers still using the meanwhile unsupported OPTIMAX v6.2 or v6.1 shall contact ABB to identify the right way forward.

Revisionshistorie (1)
  1. Erstveröffentlichung16. Januar 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

2CRT000009

WebPro SNMP Card PowerValue Multiple Vulnerabilities

ABBUnbekanntes Produkt

ABB PSIRThoch

Veröffentlicht

7. Januar 2026

Letzte Aktualisierung

7. Januar 2026

Betroffene Sektoren

Risk Evaluation

ABB became aware of multiple internally discovered vulnerabilities in the WebPro SNMP card PowerValue for the product versions listed as affected in the advisory. Depending upon the vulnerability, an attacker with access to local network who successfully exploited this vulnerability could have - Unauthorized access - Insufficient Session Expiration leading to resource unavailability - Uncontrolled Resource Consumption leading to DOS attack ABB strongly advises customers to update the latest firmware of affected products.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product versions: WebPro SNMP card PowerValue version 1.1.8.p ABB advises users of the affected product versions to reach out to ABB Digital Service Support (ch.ups.digital@abb.com) for guidance and recommended actions. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information.

Revisionshistorie (1)
  1. Erstveröffentlichung7. Januar 2026

    Initial version.

Offizielle Quelle: ABB PSIRT

4HZM000603

ABB Ability Camera Connect Vulnerabilities in outdated 3rd party component (VLC)

ABBAbility Camera Connect

ABB PSIRTkritisch

Risk Evaluation

ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in this advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways.

Zusammenfassung der Gegenmaßnahmen

The VLC-based component operates solely within completely isolated environments without internet access or any connectivity to external networks. Consequently: • No exposure to untrusted MMS streams: The integer overflow vulnerability relies on handling a maliciously crafted external stream, which is not possible in isolated environments • No remote attacker access: Without network ingress, attackers cannot trigger the vulnerability remotely. • Drastically reduced attack surface: The absence of any external media inputs effectively neutralizes the exploit path, significantly lowering the risk of both denial of service and code execution.

Revisionshistorie (2)
  1. Erstveröffentlichung27. November 2025

    Initial version.

  2. Update A28. November 2025

    Correction in References

Offizielle Quelle: ABB PSIRT

7PAA022088

Edgenius Management Portal Authentication Bypass

ABBAbility Edgenius

ABB PSIRTkritisch

Veröffentlicht

20. November 2025

Letzte Aktualisierung

20. November 2025

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB identified a critical vulnerability present in ABB Ability Edgenius starting from version 3.2.0.0. We have not received any reports of this vulnerability being exploited. An unauthenticated attacker could exploit this vulnerability to: → install and run arbitrary code, → uninstall installed applications, → modify the configuration of installed applications, on systems running the vulnerable versions of ABB Ability Edgenius, including 3.2.0.0 through 3.2.1.1.

Zusammenfassung der Gegenmaßnahmen

ABB has prepared an update to fix this vulnerability included in the latest Roll-Up, ABB Ability Edgenius version 3.2.2.0. ABB advises customers to upgrade as soon as possible. Until the upgrade is applied, ABB advises customers to disable the Edgenius Management Portal to mitigate the vulnerability.

Revisionshistorie (1)
  1. Erstveröffentlichung20. November 2025

    Initial version.

Offizielle Quelle: ABB PSIRT

2NGA002813

PCM600 SharpZip library vulnerability

ABBUnbekanntes Produkt

ABB PSIRTmiddel

Veröffentlicht

3. November 2025

Letzte Aktualisierung

3. November 2025

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

An update is available that resolves vulnerability in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could insert and run arbitrary code in the system.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the following product version: ABB Protection and control IED manager PCM600 version 2.14. ABB recommends that customers apply the update at earliest convenience. Note: RE_630 protection relays are not compatible with PCM600 version 2.14. When using earlier PCM600 versions with RE_630, the known vulnerability must be mitigated through system-level defenses. For mitigation guidance, refer to the General Security Recommendations.

Revisionshistorie (1)
  1. Erstveröffentlichung3. November 2025

    Initial version.

Offizielle Quelle: ABB PSIRT

4TZ00000006007

ALS-mini-S4/S8 IP Missing Authentication Vulnerability and its Mitigations

ABBALS-mini-s4 IP

ABB PSIRTkritisch

Veröffentlicht

20. Oktober 2025

Letzte Aktualisierung

23. Oktober 2025

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.

Zusammenfassung der Gegenmaßnahmen

ABB recommends that customers correctly configure the device in the network by referring to section Mitigating factors, or apply Workarounds to completely eliminate the attack vector.

Revisionshistorie (2)
  1. Erstveröffentlichung20. Oktober 2025

    Initial version.

  2. Update A23. Oktober 2025

    Updated CVSS 3.1 score

Offizielle Quelle: ABB PSIRT

9AKK108471A8948

Terra AC wallbox Heap Memory Corruption Vulnerability

ABBTerra AC wallbox (UL40/80A)

ABB PSIRTmiddel

Veröffentlicht

20. Oktober 2025

Letzte Aktualisierung

21. Oktober 2025

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior.

Zusammenfassung der Gegenmaßnahmen

The problem is corrected in the product versions listed as fixed in the advisory. Terra AC wallbox (UL40/80A) 1.8.33 Terra AC wallbox (UL32A) 1.8.34 Terra AC MID 1.8.34 Terra AC Juno CE 1.8.34 Terra AC PTB 1.8.33 Terra AC wallbox (JP) 1.8.34 Additionally, we strongly recommend not use unsafe mode(http) to connect your charger to your backend even though OCPP is allowed to do in this way, which absolutely could be attacked by malicious man or organization as a common knowledge. ABB recommends that customers apply the update at earliest convenience.

Revisionshistorie (2)
  1. Erstveröffentlichung20. Oktober 2025

    Initial version.

  2. Update A21. Oktober 2025

    Final version

Offizielle Quelle: ABB PSIRT

3KXG200000R4801

CoreSense™ HM and CoreSense™ M10 File Path Traversal Vulnerability

ABBUnbekanntes Produkt

ABB PSIRThoch

Veröffentlicht

16. April 2025

Letzte Aktualisierung

20. Oktober 2025

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

An update is available that resolves vulnerability in the product versions listed as affected in this advisory. A path traversal vulnerability in these products can allow unauthenticated users to gain access to restricted directories. Exploiting this vulnerability can lead to complete system compromise and exposure of sensitive information.

Zusammenfassung der Gegenmaßnahmen

The vulnerabilities are corrected in the following version: CoreSense™ HM v2.3.4 & CoreSense™ M10 v1.4.1.31 ABB recommends that customers apply the update at the earliest convenience.

Revisionshistorie (4)
  1. Erstveröffentlichung16. April 2025

    Initial version.

  2. Update A30. September 2025

    Addressed comments.

  3. Update B7. Oktober 2025

    Fixed incorrect links.

  4. Update C20. Oktober 2025

    Final version with corrected dates.

Offizielle Quelle: ABB PSIRT

4TZ00000006008

LVS MConfig Insecure memory handling

ABBUnbekanntes Produkt

ABB PSIRThoch

Veröffentlicht

8. Oktober 2025

Letzte Aktualisierung

8. Oktober 2025

Verknüpfte CVEs

Betroffene Sektoren

Risk Evaluation

ABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits vulnerability could have access to application’s sensitive information. ABB strongly advises customers to update MConfig with latest software version.

Zusammenfassung der Gegenmaßnahmen

The vulnerability is resolved in the following product versions: MConfig version 1.4.9.22 ABB advises users to update their devices to the latest software version. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information

Revisionshistorie (1)
  1. Erstveröffentlichung8. Oktober 2025

    Initial version.

Offizielle Quelle: ABB PSIRT