ABB Protection and Control IED Manager PCM600

Summary

ABB's Protection and Control IED Manager PCM600 versions 2.14 and earlier are vulnerable to privilege escalation and file overwriting due to an improperly configured Scheduler Service. Exploitation requires local access and valid user credentials.

IFF Assessment

FOE

This article details vulnerabilities that could allow attackers to gain elevated privileges on critical infrastructure systems, posing a direct threat to defenders.

Severity

6.4 Medium

Defender Context

Defenders should be aware of these vulnerabilities affecting ABB's industrial control systems, particularly in the energy sector. Prioritizing patching or implementing the vendor-recommended mitigation to restrict the Scheduler Service's permissions is crucial to prevent unauthorized privilege escalation.

Read Full Story →