IM
IronMonkey Threat Research
‹ Back to ICS Advisories

mapp Services Use of Weak Authenticators in mapp Audit

HIGH
CVSS 8.7
Date 2026-09-03T00:30:00+00:00
Source abb-psirt
Published by ABB PSIRT

// Description

An update is available that resolves a vulnerability in the product versions listed as affected in the advisory. An attacker who successfully exploits this vulnerability could gain access to the OPC UA server component on affected devices due to insufficient entropy of authenticators used by mapp Audit.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-79679 8.7 high
CVE-2026-79679. A vulnerability in mapp Audit in B&R mapp Services before version 6.8.0 is caused by insufficient entropy of the authenticators, which could allow an attacker with network access to gain access to the OPC UA server functionality used by mapp Audit.

// Remediations (2)

Mitigation: The exposure is limited to systems that actively use the mapp Audit functionality. Projects that onl
The exposure is limited to systems that actively use the mapp Audit functionality. Projects that only include mapp Services, but do not configure or use mapp Audit, are not affected. The risk can be further reduced by restricting network access to the affected OPC UA server, for example by limiting access to trusted engineering stations, runtime components, or dedicated automation network segments using the Automation Runtime host-based firewall. Refer to section “General security recommendations” for further advise on how to keep your system secure.
Patch: The problem is corrected in the following product versions: mapp Services >= 6.8.0 B&R recommends
The problem is corrected in the following product versions: mapp Services >= 6.8.0 B&R recommends that customers apply the update at earliest convenience when the vulnerable functionality mapp Audit is used. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual.

// References