Kwetsbaarheden worden geladen…
Kwetsbaarheden worden geladen…
CVE-2025-14772
Broken access controls in ABB T-MAC Plus web application allows unprivileged users to performs administrative operations
Dit record: live koppeling — laatst opgehaald: 25 juli 2026 om 01:40.
Leverancier
ABB
Product
T-MAC Plus
Gepubliceerd
25 juli 2026
Laatst gewijzigd
25 juli 2026
Broken access controls in ABB T-MAC Plus web application allows unprivileged users to performs administrative operations
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack vector
NETWORK
Privileges required
LOW
User interaction
NONE
Vertrouwelijkheid
Hoog
Integriteit
Hoog
Beschikbaarheid
Hoog
Mogelijk verlies van zicht op of besturing over het proces bij succesvol misbruik.
Beoordeeld als relevant voor de energiesector op basis van: Vermeld in een officiële CISA ICS Advisory, wat directe relevantie voor industriële besturingssystemen bevestigt. Leverancier "ABB" is een bekende leverancier van apparatuur voor de energiesector.
ABB has investigated these vulnerabilities to provide adequate protection to customers. The problem is corrected in the following product versions: T-MAC Plus version 4.0-25 ABB recommends that customers apply the update at earliest convenience.
IACS Radar-duiding
Classificatie is voorlopig; handmatige verificatie door een OT-securityanalist wordt aanbevolen.
Geclassificeerd door IACS Radar-analysepijplijn (geautomatiseerd) op 25 juli 2026.
IACS Radar-duiding
IEC 62443-mapping
Automatische IACS Radar-duiding op basis van de gerapporteerde CWE-zwakteclassificatie; geen officiële certificeringsuitspraak.