ABB Ability OPTIMAX Authentication Bypass Vulnerability
CVE-2025-14510 allows an attacker to bypass Azure Active Directory Single-Sign On authentication in vulnerable ABB Ability OPTIMAX versions, potentially granting unauthorized access to critical infrastructure systems.
A critical vulnerability, CVE-2025-14510, affects ABB Ability OPTIMAX versions that utilize Azure Active Directory (Azure AD) for Single-Sign On (SSO) authentication. This flaw stems from an incorrect implementation of the authentication algorithm, potentially allowing attackers to bypass the Azure AD authentication mechanism and gain unauthorized access to the OPTIMAX system. The affected versions include ABB Ability OPTIMAX 6.1 and 6.2 (all versions), 6.3 versions prior to 6.3.1-251120, and 6.4 versions prior to 6.4.1-251120. Successful exploitation could lead to significant disruption in energy, water, and wastewater sectors. The vulnerability was reported to CISA by ABB PSIRT.
Attack Chain
- An attacker identifies an ABB Ability OPTIMAX installation using Azure AD SSO with a vulnerable version (6.1, 6.2, 6.3 < 6.3.1-251120, or 6.4 < 6.4.1-251120).
- The attacker crafts a malicious authentication request, exploiting the incorrect implementation of the authentication algorithm (CWE-303).
- The crafted request bypasses the expected Azure AD authentication checks within OPTIMAX.
- OPTIMAX incorrectly validates the attacker’s session, granting them access to the system.
- The attacker leverages their unauthorized access to gain control over OPTIMAX functionalities.
- The attacker can then modify control parameters, manipulate data, or disrupt operations within the connected industrial processes.
Impact
Successful exploitation of CVE-2025-14510 enables unauthorized access to ABB Ability OPTIMAX systems, potentially leading to severe consequences in critical infrastructure sectors such as energy, water, and wastewater. An attacker could manipulate industrial processes, disrupt critical services, or cause significant financial and operational damage. Given the widespread deployment of ABB Ability OPTIMAX systems globally, a successful campaign exploiting this vulnerability could have far-reaching impact.
Recommendation
- Immediately update ABB Ability OPTIMAX to fixed versions (6.3.1-251120 and later) to remediate CVE-2025-14510.
- Refer to ABB PSIRT security advisory 9AKK108472A1331 for detailed mitigation steps and recommendations.
- Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet, as per CISA’s recommended practices.
Detection coverage 2
Detect Attempts to Access OPTIMAX resources after Failed Azure AD Authentication
mediumThis rule detects attempts to access OPTIMAX resources immediately following a failed Azure AD authentication event, which may indicate an authentication bypass attempt.
Detect ABB OPTIMAX Unauthenticated Access Attempts
highDetects web server logs indicating attempts to access ABB OPTIMAX resources without proper authentication.
Detection queries are kept inside the platform. Get full rules →