Two ABB PCM600 Weaknesses Put Windows Privileges and Project Files at Risk

CISA disclosed two ABB PCM600 flaws enabling Windows privilege escalation and path traversal in project imports. Learn affected versions and mitigations.

Two ABB PCM600 Weaknesses Put Windows Privileges and Project Files at Risk
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 10 min

CISA has disclosed two vulnerabilities in ABB Protection and Control IED Manager (PCM600) that could enable privilege escalation or files being written beyond an intended extraction directory.

The agency published ICS advisory ICSA-26-274-03 on 2026-10-01. The issues are tracked as CVE-2026-15952 and CVE-2026-15953.

Both vulnerabilities affect PCM600 from version 0 through 2.14. CISA expresses the same range as PCM600 2.14 and earlier, without identifying narrower affected build numbers.

ABB, named in the CVE records as Asea Brown Boveri Ltd., is the CVE Numbering Authority for both entries. The records were published and updated on 2026-09-28.

Energy-sector installations face two distinct attack paths

PCM600 is ABB’s Protection and Control IED Manager. CISA associates deployments of the product with the energy sector and reports that it is used worldwide. ABB is headquartered in Switzerland.

The vulnerabilities affect separate PCM600 functions:

  • CVE-2026-15952 concerns permissions surrounding a highly privileged Windows service. An attacker with local access and valid credentials could potentially elevate privileges and control the host.
  • CVE-2026-15953 concerns the extraction of PCM600 project archives. Inadequate path validation could direct files outside the directory selected for extraction.

The first issue provides a possible route from existing local access to broader operating-system control. The second threatens filesystem integrity when PCM600 processes a project archive containing unsafe entry paths.

CISA said that, as of its 2026-10-01 advisory, it had received no reports of public exploitation specifically targeting either vulnerability. That statement describes the information available to the agency at publication; it does not prove that exploitation has never occurred.

The supplied NVD excerpt does not provide a Known Exploited Vulnerabilities catalog status or remediation deadline for either CVE. Their KEV status therefore cannot be established from that material.

Scheduler permissions could expose LocalSystem privileges

The CVE Program record for CVE-2026-15952 names the issue “Improper Permission Assignment in Scheduler Service.”

PCM600 installs a Scheduler Service that operates as LocalSystem, a Windows context with extensive privileges. Standard PCM600 users receive permissions through membership in the machine’s local users group.

According to CISA, an attacker who already possesses local access and valid user credentials may be able to abuse this configuration to elevate privileges. Successful exploitation could ultimately give that attacker control of the affected Windows host.

The vulnerability is assigned CWE-732. Its severity changes between the two CVSS specifications recorded by ABB:

  • CVSS v3.1: 6.4, Medium
    CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
  • CVSS v4.0: 7.1, High
    CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

The CVSS v3.1 vector characterizes the attack as local, requiring high privileges and high complexity but no additional user interaction. A successful compromise can have high consequences for confidentiality, integrity and availability.

This is not described as an unauthenticated remote attack. The exposure instead matters when an attacker or malicious user has already gained a foothold on a workstation running an affected PCM600 version.

Project archive imports can write beyond their destination

The CVE Program calls CVE-2026-15953 “Path Traversal During Project Archive Import.”

PCM600 fails to apply sufficient validation to paths contained in project archive entries. During extraction, an unsafe entry may therefore resolve to a location outside the directory where the archive was supposed to be unpacked.

That behavior could allow files to be written elsewhere on the filesystem. The issue is categorized as CWE-22, the weakness class covering failures to keep pathname operations within an authorized directory.

Its severity metrics are:

  • CVSS v3.1: 5.0, Medium
    CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
  • CVSS v4.0: 5.6, Medium
    CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N

Under CVSS v3.1, the vulnerability has a local attack vector, low complexity, low privilege requirements and required user interaction. Its recorded impact is concentrated on integrity rather than confidentiality or availability.

CISA’s summary table assigns PCM600 a single CVSS v3 score of 6.4 while listing both weakness classes. That product-level presentation should not be mistaken for the individual score of CVE-2026-15953, which is 5.0 under CVSS v3.1.

Changing the Scheduler account reduces escalation risk

CISA provides a configuration workaround for CVE-2026-15952. It reduces the potential impact of the permissions issue but does not repair the underlying vulnerability.

Administrators should configure the relevant PCM600 Scheduler Service to use the same Windows account that operates PCM600:

  1. Open Services.msc.
  2. Find the ABBPCMSchedulerService instance corresponding to the installed PCM600 version.
  3. Open Properties and select the Log On tab.
  4. Configure the service to run with the same Windows account used for PCM600.
  5. Ensure that the selected account has the Log on as a service privilege.

Replacing the LocalSystem logon context with the PCM600 user account limits the privileges available to the service. CISA also includes this configuration in its mitigation guidance for CVE-2026-15953.

If authentication is enabled for an IED, operators should use the Scheduler tool through the same Windows identity configured as the Scheduler Service logon account.

CISA directs customers to ABB security advisories 2NGA003170 and 2NGA003179. The CVE records associate 2NGA003170 with CVE-2026-15952 and 2NGA003179 with CVE-2026-15953.

Certificate trust and network isolation add defensive layers

For environments using IED security certificates, CISA says the PCM600 setting Always trust IED security certifcates should be enabled only when PCM600-to-IED communications take place in a secure and trusted environment. The spelling of certifcates is the literal setting name reproduced in the advisory.

Organizations should first identify PCM600 installations and verify whether they run version 2.14 or earlier. Any service-account change should undergo an operational impact and risk assessment before deployment, particularly in control-system environments.

CISA also recommends limiting network exposure for industrial systems. Control-system devices should not be directly reachable from the internet, while operational networks and remote equipment should be placed behind firewalls and isolated from business networks.

Where remote access is necessary, organizations should use secured methods such as VPNs and keep the relevant software current. The security of endpoints connecting through a VPN must also be considered, because the encrypted connection does not protect the environment from an already compromised client.

Reporting and attribution

CISA credits Abhinav Agarwal with reporting both vulnerabilities.

Organizations that detect suspected malicious activity involving PCM600 should follow their established internal response procedures and report relevant findings to CISA. Administrators should also treat unsolicited links, email attachments and project archives cautiously, especially where opening or importing content could satisfy the user-interaction condition recorded for CVE-2026-15953.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →