IM
IronMonkey Threat Research
‹ Back to ICS Advisories

ABB Protection and Control IED Manager (PCM600) - PCM600 Project Import Path Traversal

MEDIUM
CVSS 5.0
Date 2026-09-28T00:30:00+00:00
Source abb-psirt
Published by ABB PSIRT

// Description

ABB is aware of a privately reported vulnerability affecting the PCM600 project import functionality. An update is available that resolves this vulnerability in the affected product versions. A specially crafted PCM600 project archive may exploit insufficient validation of archive entry paths during project import. Successful exploitation could allow an attacker to create or overwrite files outside the intended extraction directory using the permissions of the importing user.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-15953 5.0 medium
CVE-2026-15953. A vulnerability exists in the processing of PCM600 project archives files. Insufficient validation of archive entry paths may permit path traversal during extraction, potentially allowing files to be written to locations outside the intended extraction directory.

// Remediations (2)

Patch: The problem is corrected in the following product version: - ABB Protection and Control IED Manager
The problem is corrected in the following product version: - ABB Protection and Control IED Manager (PCM600) version 2.14 Hotfix 20260923. This fixed version is available through the ABB Update Manager and ABB website: PCM600 | ABB ABB recommends that customers upgrade to the available hotfix at the earliest opportunity. Until the update can be applied, customers should follow the mitigation measures described in this advisory.
Mitigation: The risk is significantly reduced when PCM600 is configured with High Security Level, as unsigned pr
The risk is significantly reduced when PCM600 is configured with High Security Level, as unsigned project files cannot be imported. As a result, attackers cannot rely on users importing manipulated unsigned archives. Organizations that restrict project imports to trusted sources and enforce High Security Level settings substantially reduce exposure to this vulnerability. Refer to section “General security recommendations” for further advise on how to keep your system secure.

// References