IM
IronMonkey Threat Research
‹ Back to ICS Advisories

ABB Protection and Control IED Manager PCM600

MEDIUM
CVSS 6.4
Date 2026-10-01T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2026-15952 6.4 medium
A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host.
CVE-2026-15953 5.0 medium
A vulnerability exists in the processing of PCM600 project archives files. Insufficient validation of archive entry paths may permit path traversal during extraction, potentially allowing files to be written to loca tions outside the intended extraction directory.

// Remediations (13)

Mitigation: For installations using IED security certificates, the PCM600 setting Always trust IED security cert
For installations using IED security certificates, the PCM600 setting Always trust IED security certifcates must be enabled only when PCM600-to-IED communication takes place in a secure and trusted environment.
Mitigation: Ensure that this account has the required "Log on as a service" privilege.
Ensure that this account has the required "Log on as a service" privilege.
Mitigation: When authentication is enabled for the IED, the Scheduler tool must be used with the same Windows ac
When authentication is enabled for the IED, the Scheduler tool must be used with the same Windows account configured as the Scheduler Service logon account.
Mitigation: Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that
Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600:
Mitigation: ABB recommends the following workaround. Although this workaround does not correct the underlying vu
ABB recommends the following workaround. Although this workaround does not correct the underlying vulnerability, it reduces the risk of privilege escalation.
Mitigation: For more information, see ABB security advisory 2NGA003170 and 2NGA003179.
For more information, see ABB security advisory 2NGA003170 and 2NGA003179.
Mitigation: The service should be configured to log on with the same Windows user account that is used for the P
The service should be configured to log on with the same Windows user account that is used for the PCM600 application.
Mitigation: Open Properties and select the Log On tab.
Open Properties and select the Log On tab.
Mitigation: Open Services.msc.
Open Services.msc.
Mitigation: Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version.
Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version.
Workaround: ABB recommends the following workaround. Although this workaround does not correct the underlying vu
ABB recommends the following workaround. Although this workaround does not correct the underlying vulnerability, it reduces the risk of privilege escalation. Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600. - Open Services.msc. - Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version. - Open Properties and select the Log On tab. - The service should be configured to log on with the same Windows user account that is used for the PCM600 application. - Ensure that this account has the required "Log on as a service" privilege. When authentication is enabled for the IED, the Scheduler tool must be used with the same Windows account configured as the Scheduler Service logon account. For installations using IED security certificates, the PCM600 setting Always trust IED security certificates must be enabled only when PCM600-to-IED communication takes place in a secure and trusted environment. Impact of Workaround -Scheduler functionality will operate using the privileges of the configured Windows user account rather than SYSTEM privileges. - Users may need to be granted the "Log on as a service" Windows user right. - In environments using IED security certificates, enabling Always trust IED security certificates may reduce certificate validation protections and should only be used in secure and trusted environments. - Administrative effort may be required to maintain consistent user accounts between PCM600 and the Scheduler Service.
Patch: The problem is corrected in the following product version: - ABB Protection and Control IED Manager
The problem is corrected in the following product version: - ABB Protection and Control IED Manager (PCM600) version 2.14 Hotfix 20260923. This fixed version is available through the ABB Update Manager and ABB website: PCM600 | ABB ABB recommends that customers upgrade to the available hotfix at the earliest opportunity. Until the update can be applied, customers should follow the mitigation measures described in this advisory.
Mitigation: The risk is significantly reduced when PCM600 is configured with High Security Level, as unsigned pr
The risk is significantly reduced when PCM600 is configured with High Security Level, as unsigned project files cannot be imported. As a result, attackers cannot rely on users importing manipulated unsigned archives. Organizations that restrict project imports to trusted sources and enforce High Security Level settings substantially reduce exposure to this vulnerability. Refer to section “General security recommendations” for further advise on how to keep your system secure.

// References