ABB PCM600 Flaws Could Enable Privilege Escalation and File Overwrite

Critical infrastructure utility monitored for cyber and operational resilience

ABB has addressed two vulnerabilities in PCM600, its protection and control engineering tool. CISA says the flaws could let a local attacker elevate privileges or cause project-archive files to be written outside the intended extraction directory.

Two different local attack paths

CVE-2026-15952 concerns permissions around a scheduler component running as LocalSystem. Under the conditions described by the advisory, a local user could exploit that arrangement to gain higher privileges. CVE-2026-15953 is a path-traversal issue in project archive handling that could place files beyond the selected extraction folder.

CISA lists PCM600 versions through 2.14 as affected and gives the vulnerabilities a maximum CVSS v3 base score of 6.4. The agency says it is not aware of public exploitation. ABB has published product security advisories and provides workaround guidance for affected deployments.

Why engineering workstations need special care

PCM600 is used in energy-sector protection and control engineering. An engineering workstation can therefore hold trusted project files and privileged access to operational assets even when it is not directly exposed to the internet. Organizations should apply ABB’s guidance, limit local administrator rights and treat imported project archives as untrusted until validated.

Before remediation, teams should back up projects and confirm recovery procedures. Afterward, review scheduled tasks, extraction directories and endpoint telemetry for unexpected files or privilege changes. SectechMedia’s energy-security coverage examines the wider operational context for protecting utility and industrial environments.

Sources

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *