{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/protection-and-control-ied-manager-pcm600-2.14/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Protection and Control IED Manager PCM600 (\u003c=2.14)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["ABB"],"content_html":"\u003cp\u003eABB Protection and Control IED Manager PCM600 versions 2.14 and earlier are affected by two vulnerabilities that impact the security of the host system. CVE-2026-15952 involves the Scheduler Service, which executes with LocalSystem privileges but permits standard PCM600 users to interact with it, enabling local privilege escalation for attackers who already possess valid user credentials. Additionally, CVE-2026-15953 relates to the processing of PCM600 project archive files; insufficient input validation of pathnames within these archives permits path traversal, which could allow an attacker to write malicious files outside of the designated extraction directory. These vulnerabilities are particularly relevant for defenders managing energy sector infrastructure where PCM600 is deployed globally. While no active exploitation has been reported, these vulnerabilities pose a significant risk to host integrity and system-level security when an attacker has already established a foothold on the local machine.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in full system compromise via privilege escalation or the unauthorized overwriting of critical system files via path traversal. This impacts energy sector organizations globally, potentially leading to the loss of integrity of the IED management platform and disruption of control system operations. There are no concrete numbers regarding current victim count, but the vulnerability is prevalent in environments running PCM600 version 2.14 or older.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform a risk assessment and impact analysis on all systems running ABB PCM600 version 2.14 or earlier.\u003c/li\u003e\n\u003cli\u003eImplement the recommended workaround by reconfiguring the ABBPCMSchedulerService to execute under the same low-privileged Windows account used for the standard PCM600 application rather than LocalSystem.\u003c/li\u003e\n\u003cli\u003eEnsure that the \u0026quot;Log on as a service\u0026quot; privilege is correctly assigned and limited to the specific service account.\u003c/li\u003e\n\u003cli\u003eRestrict access to control system networks and ensure all IED management stations are isolated from internet access.\u003c/li\u003e\n\u003cli\u003eWhen IED security certificates are in use, strictly limit the \u0026quot;Always trust IED security certificates\u0026quot; setting to trusted, secure communication environments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T17:06:34Z","date_published":"2026-10-01T17:06:34Z","id":"https://feed.craftedsignal.io/briefs/2026-10-abb-pcm600-vulns/","summary":"ABB Protection and Control IED Manager PCM600 versions 2.14 and earlier contain local privilege escalation and path traversal vulnerabilities that could allow authenticated local attackers to gain unauthorized host control or overwrite files.","title":"Privilege Escalation and Path Traversal Vulnerabilities in ABB PCM600","url":"https://feed.craftedsignal.io/briefs/2026-10-abb-pcm600-vulns/"}],"language":"en","title":"CraftedSignal Threat Feed - Protection and Control IED Manager PCM600 (\u003c=2.14)","version":"https://jsonfeed.org/version/1.1"}