IM
IronMonkey Threat Research
‹ Back to ICS Advisories

AC500 V3 - Invalid type usage in visualization

HIGH
CVSS 7.5
Date 2026-09-28T00:30:00+00:00
Source abb-psirt
Published by ABB PSIRT

// Description

An update is available that resolves publicly reported vulnerability in the products versions listed as affected in the advisory. An attacker who successfully exploited these vulnerabilities could cause a denial-of-service (DoS).

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2025-41738 7.5 high
CVE-2025-41738. A vulnerability in the runtime system's CmpVisuServer component allows attackers to cause a denial-of-service (DoS) by sending special request to the web visualization. The issue is triggered by an internal read access using a pointer of wrong type. The vulnerability can only be exploited if the web server is running.

// Affected Products (2)

Vendor Product Asset Type Purdue Level Firmware
CODESYS, GmbH Unknown engineering_workstation
L3
--
CODESYS, GmbH Unknown engineering_workstation
L3
--

// Remediations (3)

Workaround: Disable the web server, if it is enabled, but not required for the PLC operation.
Disable the web server, if it is enabled, but not required for the PLC operation.
Patch: The problem is corrected in the following product version: - AC500 V3 firmware version 3.9.1 ABB re
The problem is corrected in the following product version: - AC500 V3 firmware version 3.9.1 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and integrated into Automation Builder 2.9.1. Automation Builder 2.9.1 is available for download from the related download site. https://www.abb.com/global/en/areas/motion/digital-tools/automation-builder/software-download
Mitigation: Refer to section “General security recommendations” for further advise on how to keep your system se
Refer to section “General security recommendations” for further advise on how to keep your system secure.

// References