CISA Issues Advisory for ABB PCM600 Privilege Escalation and Path Traversal Vulnerabilities
Two CVEs affect ABB Protection and Control IED Manager PCM600 versions 2.14 and below; local access required for exploitation.
Key Takeaways
- CISA advisory ICSA-26-274-03 identifies two vulnerabilities in ABB PCM600 versions 2.14 and earlier.
- CVE-2026-15952 is a privilege escalation flaw in the Scheduler Service requiring local access and valid credentials.
- CVE-2026-15953 is a path traversal vulnerability in project archive processing that could allow file writes outside intended directories.
- Both vulnerabilities have CVSS v3.1 scores of 6.4 and 5.0 (Medium) and CVSS v4.0 scores of 7.1 and 5.6 (High and Medium).
Related Security News
CISA Advises of Sensitive Information Exposure in Johnson Controls EasyIO Neo Series Controllers
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory regarding CVE-2026-64892, a vulnerability in Johnson Controls EasyIO Neo Series EC and CW Controllers that could allow an attacker to gain access to sensitive information. The flaw stems from improper access controls in building automation controllers and impacts four specific firmware versions. Johnson Controls has released fixed firmware versions V3.3b64 (EC) and V3.3b26 (CW) to address the issue.
