Security/ ics security · abb · cisa · energy sector

Two Bugs in ABB Grid Protection Software Lack a Patch

CISA disclosed two vulnerabilities in ABB's PCM600 relay software, including a privilege escalation bug, with only workarounds available so far.

Two newly disclosed bugs in ABB's PCM600 software could let someone with basic login access take over the Windows machine running protective relays for power equipment.

CISA's advisory covers CVE-2026-15952 and CVE-2026-15953, affecting ABB Protection and Control IED Manager PCM600 version 2.14 and earlier. The first lets a local user with valid credentials escalate to full LocalSystem privileges, because the Scheduler Service runs under that powerful account while ordinary PCM600 users can reach it through the local users group. The second is a path-traversal flaw in how PCM600 unpacks project archive files, so a rigged archive could write files outside the folder it's supposed to extract into. ABB hasn't shipped a software fix for either one - it's offering workarounds instead, like running the Scheduler Service under the same account as PCM600 and only trusting IED certificates on networks you actually trust.

PCM600 configures protection and control relays inside substations and other energy infrastructure, deployed worldwide. A privilege-escalation bug on that engineering workstation isn't abstract risk - it's a foothold into the software that keeps transmission equipment protected. CISA says it has no evidence of active exploitation, but industrial-control vendors routinely take months to turn "workaround" into "patch," which means operators are stuck manually reconfiguring Windows service accounts in the meantime.

Neither bug needs internet exposure to be dangerous - just one credentialed insider, or one booby-trapped project file someone opens without checking.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →