Historical snapshot · Cybersecurity

CISA Advisories

Cybersecurity advisories and mitigation guidance for networks and critical infrastructure.

This page is an archived snapshot of the CISA Advisories feed collected on Jun 7, 2026, preserved by BioThreat Corporation. Publication dates belong to the original source; this snapshot is not a current advisory.
30 recordsOfficial source · JSON
· CISA Cybersecurity Advisory

Fourth Frontier Frontier X Mobile Application, Frontier X2

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read and write arbitrary handle values and change clinical readings, which could result in taking control of the device and lead to patient harm. The following versions of Fourth Frontier Frontier X Mobile Application, Frontier X2 are affected: Frontier X Android application vers<v15.0.0 Frontier X IOS application vers<v25.0.0…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to read and write arbitrary handle values and change clinical readings, which could result in taking control of the device and lead to patient harm. The following versions of Fourth Frontier Frontier X Mobile Application, Frontier X2 are affected: Frontier X Android application vers<v15.0.0 Frontier X IOS application vers<v25.0.0 Frontier X2 vers:all/* CVSS Vendor Equipment Vulnerabilities v3 8.8 Fourth Frontier Fourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-5768 The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range to perform unauthorized control of device functions, including starting/stopping activities, triggering vibrations, causing denial-of-service conditions, and fuzzing characteristic values to induce unexpected behavior. Additionally, the Frontier X mobile application lacks proper BLE device authentication, allowing attackers to impersonate a legitimate Frontier X2 device and connect to the application. By cloning BLE advertisements and exposing expected GATT characteristics, attackers can manipulate activity states and inject fabricated health telemetry such as breathing rate, heart rate, strain, and other health-related data into the mobile application. View CVE Details Affected Products Fourth Frontier Frontier X Mobile Application, Frontier X2 Vendor: Fourth Frontier Product Version: Fourth Frontier Frontier X Android application: <v15.0.0, Fourth Frontier Frontier X IOS application: <v25.0.0, Fourth Frontier Frontier X2: vers:all/* Product Status: known_affected Remediations Mitigation Fourth Frontier is aware of the vulnerability and is working on a fix. Users are encouraged to reach out to Fourth Frontier directly for assistance. https://fourthfrontier.com/pages/contact-usl. https://fourthfrontier.com/pages/contact-us Mitigation Frontier X/X2 devices can connect to only one app at a time; users should first connect the Frontier X/X2 device using the Frontier X app and then start the activity. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments Shakir Zari and Jerin Sunny reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. This vulnerability is not exploitable remotely. Revision History Initial Release Date: 2026-05-28 Date Revision Summary 2026-05-28 1 Initial Publication Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability CVE-2026-45321 TanStack Unspecified Vulnerability CVE-2026-48027 Nx Console Embedded Malicious Code Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose…
Read full source summary
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability CVE-2026-45321 TanStack Unspecified Vulnerability CVE-2026-48027 Nx Console Embedded Malicious Code Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

ABB Ability Camera Connect

View CSAF Summary ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in this advisory. An attacker who…
Read full source summary
View CSAF Summary ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in this advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways. The following versions of ABB Ability Camera Connect are affected: Ability Camera Connect vers:intdot/<=1.5.0.14, 1.5.0.15 CVSS Vendor Equipment Vulnerabilities v3 9.8 ABB ABB Ability Camera Connect Heap-based Buffer Overflow, Integer Underflow (Wrap or Wraparound), Out-of-bounds Write, Uncontrolled Search Path Element, Integer Overflow or Wraparound, Off-by-one Error, Out-of-bounds Read, Double Free, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use After Free Background Critical Infrastructure Sectors: Chemical, Commercial Facilities, Communications, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2024-46461 VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation The VLC-based component operates solely within completely isolated environments without internet access or any connectivity to external networks. Consequently: • No exposure to untrusted MMS streams: The integer overflow vulnerability relies on handling a maliciously crafted external stream, which is not possible in isolated environments • No remote attacker access: Without network ingress, attackers cannot trigger the vulnerability remotely. • Drastically reduced attack surface: The absence of any external media inputs effectively neutralizes the exploit path, significantly lowering the risk of both denial of service and code execution. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-122 Heap-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 8 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:F/RL:T/RC:C CVE-2023-47360 Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation • Air-gapped environments only: Camera Connect is deployed in completely isolated environments lacking any network connectivity or internet access. • No exposure to MMS streams: The vulnerability depends on processing crafted MMS streams, which cannot originate from external or internal network sources when the system is air-gapped. • Elimination of remote attack surface: Without any method for an attacker to deliver malicious media inputs, the vulnerability cannot be triggered remotely. • Strong reduction in exploitation risk: The combined absence of external media ingestion and unavailable network paths effectively neutralizes the integer underflow exploit, significantly reducing the likelihood of both denial-of-service and memory corruption scenarios. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-191 Integer Underflow (Wrap or Wraparound) Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2023-47359 Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation Given that Camera Connect is deployed exclusively in fully isolated, air-gapped environments with no internet access or external network connectivity, the following risk-reduction factors apply: • No exposure to crafted MMS streams: The exploit requires the receipt of specially crafted packets via the MMS protocol, which cannot occur without network connectivity. • Network attack vector eliminated: As the vulnerability’s CVSS vector highlights a network-based attack (AV:N), the lack of any ingress network path nullifies the attack surface. • Low likelihood of exploitation: Without access to malicious media input, there is effectively no practical method for an attacker to trigger memory corruption, making the likelihood of denial of service or arbitrary code execution negligible. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2023-46814 A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation Given that the VLC-based component is installed exclusively within air-gapped environments under strict administrative control, the following factors substantially reduce risk: • Restricted user access: Only trusted, privileged users perform installations and modifications. Standard users have no write permissions to the uninstaller directory. • No internet or network access: The exploit requires local manipulation of VLC’s uninstaller files; without external connectivity, remote coercion or manipulation is impossible. • Elimination of attacker vector: In air gapped deployments with administrative controls, un-privileged users cannot place malicious DLLs or executables in the uninstaller’s search path. • Minimized privilege escalation risk: The combination of controlled write access, absence of network exposure, and trusted user roles effectively neutralizes the binary hijacking threat, rendering successful exploitation highly unlikely. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-427 Uncontrolled Search Path Element Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-41325 An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation Camera Connect is deployed exclusively in air-gapped environments with no internet connectivity or external network access, which significantly reduces the risk: • No exposure to malicious MKV files: The exploit requires a specially crafted Matroska file. In controlled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-190 Integer Overflow or Wraparound Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2020-26664 A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation • No exposure to malicious ASF files: The exploit requires a specially crafted ASF file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2019-19721 An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation • No exposure to malicious ASF files: The exploit requires a specially crafted ASF file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-193 Off-by-one Error Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2019-13962 lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation • No exposure to malicious MKV files: The exploit requires a specially crafted MKV file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2019-13615 libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation • No exposure to malicious ASF files: The exploit requires a specially crafted ASF file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2019-13602 An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC me-dia player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer over-flow and crash) or possibly have unspecified other impact via a crafted .mp4 file. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation • No exposure to malicious ASF files: The exploit requires a specially crafted ASF file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-191 Integer Underflow (Wrap or Wraparound) Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2019-5460 Double Free in VLC versions <= 3.0.6 leads to a crash. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation • No exposure to malicious ASF files: The exploit requires a specially crafted ASF file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-415 Double Free Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2019-5459 An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation • No exposure to malicious ASF files: The exploit requires a specially crafted ASF file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-191 Integer Underflow (Wrap or Wraparound) Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.1 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H CVE-2019-5439 A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation • No exposure to malicious ASF files: The exploit requires a specially crafted ASF file. In con-trolled environments without external media sources, such files cannot be introduced. • Remote attack vector eliminated: The vulnerability’s CVSS vector indicates a network-based attack scenario, which is impossible without connectivity. • Strict operational controls: Media ingestion is limited to trusted sources under administrative supervision, further minimizing the likelihood of malicious file introduction. • Effective risk reduction: These combined factors render exploitation highly improbable, neutralizing the buffer overflow threat. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2018-11529 VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can lever-age to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation The affected software is deployed exclusively in isolated environments with no internet connectivity and restricted external access. Exploitation of this vulnerability requires a user to open a specially crafted MKV file provided by an attacker. Since the system operates in a controlled network without exposure to untrusted sources, the likelihood of receiving and executing malicious media files is significantly reduced. Additionally, operational procedures can enforce the use of trusted media files only, further minimizing the risk. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-416 Use After Free Metrics CVSS Version Base Score Base Severity Vector String 3.1 8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-17670 In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in mod-ules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation The affected VLC component is deployed exclusively in fully isolated, air gapped environments with no internet connectivity and tightly controlled external sources. Exploitation of CVE 2017 17670 re-quires a user to open a specifically crafted MP4 file containing a type conversion error in the demuxer. Since the system only processes trusted media files—validated through internal procedures and se-cured media channels—the probability of exposure to hostile MP4 content is minimal. Therefore, the risk of successful exploitation is significantly mitigated by the restricted deployment context. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-416 Use After Free Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-10699 avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation No network-based exposure: The vulnerability requires an external actor to supply malicious media content. With no Internet connectivity and presumably controlled file sources, the risk of loading un-trusted files is minimal. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2017-9301 plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid read and application crash) or possibly have unspecified other impact via a crafted file. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation This vulnerability affects the libmpgatofixed32_plugin.dll module in VLC 2.2.4, which is responsible for decoding MPEG audio streams. The software in question does not process audio files or use any functionality related to audio decoding, meaning the vulnerable component is never invoked during normal operation. Additionally, the deployment environment is fully offline with no internet connectivity, and media ingestion is restricted to trusted internal sources. As a result, the attack surface for this vulnerability is effectively nonexistent, and the risk of exploitation is negligible under these conditions. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-9300 plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation This vulnerability affects VLC’s FLAC audio processing component. Camera Connect does not handle or process audio files, meaning the vulnerable code path is never executed during normal operation. Combined with the fact that the deployment environment is fully isolated (air gapped) and does not allow external file transfers from untrusted sources, the likelihood of exploitation is effectively eliminated. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-8313 Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation Even though the affected VLC version (2.2.4) contains this vulnerability, the software is deployed in fully air-gapped environments with no external or internet-facing connectivity. As a result, the likeli-hood of exploiting this vulnerability is extremely low. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2017-8312 Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation Because the affected VLC version (2.2.4) suffers from a heap out of bound read in the ParseJSS function—allowing an attacker to read uninitialized heap data via a crafted subtitles file—the risk of external exploitation is significantly reduced in your environment. Since the software is installed in strictly isolated systems with no internet access, no external attacker can deliver malicious subtitle files re-motely. Consequently, the only remaining exposure is local: an insider would need to intentionally load a crafted subtitle file to trigger the issue—a scenario considered highly unlikely under current governance and usage controls. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVE-2017-8311 Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation Since the application is deployed exclusively in isolated, air-gapped environments with no external network connectivity, the attack vector—specifically, the ability for an attacker to deliver a crafted subtitle file—is significantly constrained. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-8310 Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file. View CVE Details Affected Products ABB Ability Camera Connect Vendor: ABB Product Version: ABB Ability Camera Connect <=1.5.0.14 Product Status: fixed, known_affected Remediations Mitigation Because your team’s VLC based software is deployed only in isolated environments without internet access, the risk of malicious delivery of crafted subtitle files is greatly diminished. This significantly reduces exploitation likelihood. Vendor fix The problem is corrected in the following product versions: ABB Ability Camera Connect 1.5.0.15 The 3rd party component has already been updated. The easiest path to mitigate the problem is an update of just VLC Media Player by the customer. ABB recommends that customers apply the update at earliest convenience. It is also possible to update to the latest Version of Camera Connect. Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Acknowledgments ABB PSIRT reported these vulnerabilities to CISA. Notice The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners. Frequently Asked Questions What causes the vulnerability? The vulnerability is caused by unchecked input data in the VLC media player in Camera Connect What is ? VLC media player What might an attacker use the vulnerability to do? An attacker who successfully exploited this vulnerability could cause the affected system node to stop or become inaccessible and allow the attacker to insert and run arbitrary code . How could an attacker exploit the vulnerability? An attacker could try to exploit the vulnerability by creating a specially crafted file, copying the file to affected system nodes and then manually open the file via VLC Mediaplayer. This would require that the attacker has access to the system network, by connecting to the network either directly or through a wrongly configured or penetrated firewall, or that he installs malicious software on a system node or otherwise infects the network with malicious software. Recommended practices help mitigate such attacks, see section Mitigating Factors above. Could the vulnerability be exploited remotely? No, to exploit this vulnerability an attacker would need to have physical access to an affected system node. Can functional safety be affected by an exploit of this vulnerability? While these vulnerabilities primarily impact confidentiality, integrity, and availability, they do not directly affect functional safety in the traditional sense. However, a compromised system (due to arbitrary code execution or a critical service crash) may compromise safety-related processes dependent on VLC, potentially disrupting business operations or compliance. What does the update do? The update removes the vulnerability by providing a newer version of the VLC media player When this security advisory was issued, had this vulnerability been publicly disclosed? This vulnerability has been publicly disclosed for the 3rd party component, but not for the ABB product using this component When this security advisory was issued, had ABB received any reports that this vulnerability was being exploited? No, ABB had not received any information indicating that this vulnerability had been exploited when this security advisory was originally issued. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of ABB PSIRT 4HZM000603 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory. Revision History Initial Release Date: 2025-11-27 Date Revision Summary 2025-11-27 1 Initial version. 2025-11-28 2 Correction in References 2026-05-26 3 Initial CISA Republication of ABB PSIRT 4HZM000603 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)

View CSAF Summary An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could cause the product to stop. The following versions of ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) are affected: Automation Runtime <6.3…
Read full source summary
View CSAF Summary An update is available that resolves a vulnerability identified by B&Rs internal security analysis in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could cause the product to stop. The following versions of ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) are affected: Automation Runtime <6.3 Automation Runtime <Q4.93 CVSS Vendor Equipment Vulnerabilities v3 10 B&R ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) Improper Resource Locking Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-3450 An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions. View CVE Details Affected Products ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) Vendor: B&R Product Version: Automation Runtime <6.3, Automation Runtime <Q4.93 Product Status: fixed, known_affected Remediations Vendor fix The problem is corrected in Automation Runtime versions 6.3 and Q4.93. The System Diagnostic Manager (SDM) is disabled by default in Automation Runtime 6 and is not in-tended be enabled on active systems located outside properly secured production networks or in facilities lacking adequate physical and logical access controls to prevent any form of unauthorized interaction. For customers who use SDM on their systems, B&R recommends applying the update at the earliest convenience. The process to install updates is described in the user manual. The step to identify the installed product version is described in the user manual. Relevant CWE: CWE-413 Improper Resource Locking Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H/E:U/RL:O/RC:C Acknowledgments ABB PSIRT reported this vulnerability to CISA. Notice The information in this document is subject to change without notice, and should not be construed as a commitment by B&R. B&R provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall B&R or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if B&R or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from B&R, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners. Mitigating factors Deactivate the vulnerable component The SDM is deactivated by default on Automation Runtime version >=6.0. For Automation Runtime versions <6.0, the SDM can be deactivated in the Automation Studio project. Please refer to Automation Help GUID 1d915d67-07f7-4034-a472-c204b5cabbfe for further guidance. Access to the System Diagnostic Manager (SDM) shall be restricted to trusted personnel through appropriate external security measures. If SDM is required solely for maintenance purposes, it should be enabled or access granted only for the minimum time necessary to perform the task. Limit accessibility B&R recommends in general to configure the HTTP protocol over TLS (HTTPS). Customers may restrict access to the webserver by configuring mutual TLS (mTLS) in the Automation Studio project (Option “Validate SSL communication partner”). Be aware that configuring mTLS would impact also other applications using the AR webserver (e.g. mapp View). Please refer to Automation Help GUID 01ced6c0-28ef-4aaa-bd05-2442b971859c to learn more about the TLS Configuration in Automation Studio. In addition, accessibility of the webserver can be limited to trusted IP addresses using the Automation Runtime host-based firewall. Please refer to Automation Help GUID 75b8994b-f97a-4e0f-8278-43c7a737e65f for details. Refer to section “General security recommendations” for further advise on how to keep your system secure. Frequently asked questions What causes the vulnerability? The vulnerabilities are caused by improper resource locking. What is System Diagnostics Manager (SDM)? System Diagnostics Manager (SDM) is a webpage available over the Automation Runtime Webserver, showing key diagnostic information of the running controller What is Automation Runtime (AR)? B&R Automation Runtime is a middleware system enabling customers to run applications on B&R target systems. What might an attacker use the vulnerability to do? An attacker who successfully exploited these vulnerabilities could cause the affected system node to stop. How could an attacker exploit the vulnerability? An attacker could try to exploit the vulnerability by creating a specially crafted message and sending the message to an affected system node. This would require that the attacker has access to the system network, by connecting to the network either directly or through a wrongly configured or penetrated firewall, or that he installs malicious software on a system node or otherwise infects the network with malicious software. Recommended practices help mitigate such attacks, see section Mitigating Factors above. Could the vulnerability be exploited remotely? Yes, an attacker who has network access to an affected system node could exploit this vulnerability. Recommended practices include that process control systems are physically protected, have no direct connections to the Internet, and are separated from other networks by means of a firewall system that has a minimal number of ports exposed. When this security advisory was issued, had this vulnerability been publicly disclosed? No, B&R discovered the vulnerabilities through its own security analysis. When this security advisory was issued, had B&R received any reports that this vulnerability was being exploited? No, B&R had not received any information indicating that this vulnerability had been exploited when this security advisory was originally issued. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of ABB PSIRT SA25P002 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory. Revision History Initial Release Date: 2025-10-07 Date Revision Summary 2025-10-07 1 Initial version. 2026-05-26 2 Initial CISA Republication of ABB PSIRT SA25P002 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of…
Read full source summary
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
· CISA Cybersecurity Advisory

ABB LVS MConfig

View CSAF Summary ABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits vulnerability could have access to application’s sensitive information. ABB strongly advises customers to update MConfig with latest software version. The following versions of ABB LVS MConfig are affected:…
Read full source summary
View CSAF Summary ABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits vulnerability could have access to application’s sensitive information. ABB strongly advises customers to update MConfig with latest software version. The following versions of ABB LVS MConfig are affected: LVS <=1.4.9.21 CVSS Vendor Equipment Vulnerabilities v3 7.4 ABB ABB LVS MConfig Cleartext Storage of Sensitive Information in Memory Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy, Food and Agriculture, Transportation Systems, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-9970 During the runtime of the MConfig Software application, an attacker can export the memory dump file into the operating system. If passwords are stored in plain text in memory, they will be included in these dump files. If such dump files are mishandled, attackers could obtain them and extract the passwords. View CVE Details Affected Products ABB LVS MConfig Vendor: ABB Product Version: MConfig Version <=1.4.9.21 Product Status: fixed, known_affected Remediations Vendor fix The vulnerability is resolved in the following product versions: MConfig version 1.4.9.22 ABB advises users to update their devices to the latest software version. Additionally, ABB recommends implementing defensive measures to reduce the risk of vulnerability exploitation, as outlined in the product instruction manual. Please refer to the section “Mitigation factors” for more information Relevant CWE: CWE-316 Cleartext Storage of Sensitive Information in Memory Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.4 HIGH CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:H/E:P/RL:O/RC:C/CR:L/IR:L/AR:L Acknowledgments ABB PSIRT reported this vulnerability to CISA. Notice The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third-party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners. Mitigating factors Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. In case customer cannot upgrade the firmware or it is not feasible then please immediately apply mitigating factors mentioned in “General security recommendations”. Frequently asked questions What causes the vulnerability? The vulnerability is caused by code defect allowing the attacker to extract the sensitive information such as user credentials from memory dump of the application. Please refer to Vulnerability severity and details for further details. What is MConfig ? MConfig is the parameterizing software for ABB LV switchgear components such as motor and feeder controller, operation panel, temperature monitoring solutions and protocol converter. The components are physically installed in a low voltage switchgear located in switch rooms that require authority to access. To run this software on a host machine (computer), the operating system should be Win11 or later version. What might an attacker use the vulnerability to do? If the mentioned vulnerability has been successfully exploited by an attacker, this could allow the attacker to extract sensitive information such as user credentials. With user credentials and access to a host machine with MConfig installed, and access to the switch room with components installed in a switchgear, the attacker can modify the setting of the components potentially compromising its correct operation. How could an attacker exploit vulnerability? An attacker with host machine physical access could, after a user log into MConfig, exploit a vulnerability by exporting a memory dump during runtime, potentially exposing the user's password. Could vulnerability be exploited remotely? The vulnerability can only be exploited if an attacker has physical access to the host machine with MConfig software. What does the update do? MConfig version V1.4.9.22 update has fix for the vulnerability mentioned in Vulnerability severity and details section. The measures below were implemented to fix the vulnerability: • Clear any authentication-related memory data after a successful login. • Hash the passwords in SHA256 Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of ABB PSIRT 4TZ00000006008 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory. Revision History Initial Release Date: 2025-10-08 Date Revision Summary 2025-10-08 1 Initial version. 2026-05-26 2 Initial CISA Republication of ABB PSIRT 4TZ00000006008 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

ABB AC500 V2

View CSAF Summary ABB became aware of vulnerabilities in AC500 V2 listed as affected in the advisory. An attacker who successfully exploited this vulnerability could access fragments of Modbus telegrams that have been sent earlier by that PLC The following versions of ABB AC500 V2 are affected: AC500 V2 <=2.5.2, 2.5.3 CVSS Vendor Equipment Vulnerabilities v3 5.8 ABB ABB AC500 V2 Buffer Over-read Background Critical…
Read full source summary
View CSAF Summary ABB became aware of vulnerabilities in AC500 V2 listed as affected in the advisory. An attacker who successfully exploited this vulnerability could access fragments of Modbus telegrams that have been sent earlier by that PLC The following versions of ABB AC500 V2 are affected: AC500 V2 <=2.5.2, 2.5.3 CVSS Vendor Equipment Vulnerabilities v3 5.8 ABB ABB AC500 V2 Buffer Over-read Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-7745 Sending unsupported function codes to the AC500 V2 Modbus server might result in invalid responses. Fragments of previous responses might be added to the end of the response. View CVE Details Affected Products ABB AC500 V2 Vendor: ABB Product Version: ABB AC500 V2 <=2.5.2 Product Status: fixed, known_affected Remediations Vendor fix The vulnerabilities have been resolved in the following product versions: AC500 V2 firmware version 2.5.3 (released in 2016) and later Relevant CWE: CWE-126 Buffer Over-read Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.8 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N Acknowledgments Reid Wightman of Dragos. Inc reported these vulnerabilities to Schneider Electric. Notice The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners. Mitigating factors Mitigating factors describe conditions and circumstances that make an attack that exploits the vulnerability difficult or less likely to succeed. Regarding this vulnerability it is recommended to • Do not use the Modbus server for sending any sensitive data, as fragments might be accessible even after the initial sending of the response • Only use supported Modbus function codes, as invalid responses to unsupported function codes might have negative effects on the requesting Modbus client. Refer to section “General security recommendations” for further advise on how to keep your system secure. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of ABB PSIRT 3ADR011432 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory. Revision History Initial Release Date: 2025-07-23 Date Revision Summary 2025-07-23 1 Initial version. 2026-05-22 2 Minor correction to the affected product version in the product tree. 2026-05-26 3 Initial CISA Republication of ABB PSIRT 3ADR011432 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

ABB Terra AC

View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior. The following versions of ABB Terra AC are affected: Terra AC wallbox…
Read full source summary
View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of the product and performs a write operation to the flash memory to alter the firmware behavior. The following versions of ABB Terra AC are affected: Terra AC wallbox (UL40/80A) <=1.8.32, 1.8.33 Terra AC wallbox (UL32A) <=1.8.2, 1.8.34 Terra AC wallbox (MID/ CE) <=1.8.32, 1.8.34 Terra AC wallbox (JP) <=1.8.2, 1.8.34 CVSS Vendor Equipment Vulnerabilities v3 6.8 ABB ABB Terra AC Heap-based Buffer Overflow Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-5517 There is potential risk to pollute the memory when a specially crafted OCPP message may be sent to a target vulnerable charger by exploiting unencrypted communication to the Charging Station Management System (CSMS) or fully remotely from its CSMS server. View CVE Details Affected Products ABB Terra AC Vendor: ABB Product Version: ABB Terra AC wallbox (UL40/80A) <=1.8.32, ABB Terra AC wallbox (UL32A) <=1.8.2, ABB Terra AC wallbox (MID/ CE) Terra AC MID <=1.8.32, ABB Terra AC wallbox (JP) <=1.8.2 Product Status: fixed, known_affected Remediations Vendor fix The problem is corrected in the product versions listed as fixed in the advisory. Terra AC wallbox (UL40/80A) 1.8.33 Terra AC wallbox (UL32A) 1.8.34 Terra AC MID 1.8.34 Terra AC Juno CE 1.8.34 Terra AC PTB 1.8.33 Terra AC wallbox (JP) 1.8.34 Additionally, we strongly recommend not use unsafe mode(http) to connect your charger to your backend even though OCPP is allowed to do in this way, which absolutely could be attacked by malicious man or organization as a common knowledge. ABB recommends that customers apply the update at earliest convenience. Relevant CWE: CWE-122 Heap-based Buffer Overflow Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C Acknowledgments Itai Shmueli of Saiflow reported this vulnerability to Schneider Electric. Notice The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners. Mitigating factors To attack with this kind of message, hackers must hijack CSMS (OCPP backends) first and then can send messages, OR the way to OCPP backend is unsafe itself (http) which can cause any kind of attack behavior and known as a common knowledge. Refer to section “General security recommendations” for further advise on how to keep your system secure. Workarounds Make sure OCPP backend that chargers are connected is strictly secured to avoid any kind of at-tack especially the communication relevant components. Use https(TLS) as basic communication foundation between charger and OCPP backend instead of http. Frequently asked questions What causes the vulnerability? The vulnerability is caused by firmware which it didn’t limit the length of OCPP field in certain case. What is Terra AC wallbox? Terra AC wallbox is a Level 2 Electric Vehicle charger. What might an attacker use the vulnerability to do? An attacker who successfully exploited this vulnerability could cause the affected system node to take control of the charger to response wrong messages, Denial-of-Service, compromised internal state, and possibly remote code execution. How could an attacker exploit the vulnerability? An attacker could try to exploit the vulnerability by sending a specially crafted OCPP message to chargers via OCPP backend(CSMS), which could be done remotely. This would require that the attacker has access to the system network and hijack the API of sending message OR hijack the network data directly if the charger is connected with unsafe http mode. Recommended practices help mitigate such attacks, see section Mitigating Factors above. Could the vulnerability be exploited remotely? Yes, an attacker who has network access to an affected system node could exploit this vulnerability. Can functional safety be affected by an exploit of this vulnerability? The charger potentially is running with unpredictable mode, including Denial-of-Service, compromised internal state, and possibly remote code execution. What does the update do? The update removes the vulnerability by modifying the validation rules of receiving data from OCPP backend. When this security advisory was issued, had this vulnerability been publicly disclosed? No, ABB received information about this vulnerability through responsible disclosure. When this security advisory was issued, had ABB received any reports that this vulnerability was being exploited? No, ABB had not received any information indicating that this vulnerability had been exploited when this security advisory was originally issued Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of ABB PSIRT 9AKK108471A8948 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory. Revision History Initial Release Date: 2025-10-20 Date Revision Summary 2025-10-20 1 Initial version. 2025-10-21 2 Final version 2026-05-26 3 Initial CISA Republication of ABB PSIRT 9AKK108471A8948 advisory Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

ABB Ability Zenon Remote Transport Vulnerability (Update A)

View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. The vulnerability enables unauthorized access to the Reboot OS function within the Remote Transport Service, allowing an attacker to trigger a system reboot without the required authentication. This functionality initiates a system reboot on the target machine. However, remote exploitation of this…
Read full source summary
View CSAF Summary ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. The vulnerability enables unauthorized access to the Reboot OS function within the Remote Transport Service, allowing an attacker to trigger a system reboot without the required authentication. This functionality initiates a system reboot on the target machine. However, remote exploitation of this vulnerability is not feasible unless the attacker has already gained access to the network where the affected ABB Ability Zenon system is deployed. At the time of writing, there is no evidence that this vulnerability is being actively exploited in the wild. The following versions of ABB Ability Zenon Remote Transport Vulnerability are affected: Ability Zenon >=7.50|<=14 CVSS Vendor Equipment Vulnerabilities v3 7.5 ABB ABB Ability Zenon Remote Transport Vulnerability Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-8754 In the default configuration of the ABB Zenon software platform, the zensyssrv.exe service is set to start automatically. To utilize the Remote Transport Service, users are required to configure a password beforehand. However, a security vulnerability has been identified that enables unauthorized attackers to bypass authentication mechanisms and remotely initiate a system reboot without proper authorization View CVE Details Affected Products ABB Ability Zenon Remote Transport Vulnerability Vendor: ABB Product Version: ABB Ability Zenon >=7.50|<=14 Product Status: known_affected Remediations Workaround • Restrict network access to systems with the ABB Zenon Software Platform installed. - Ensure that access to a system is restricted by implementing access controls to minimize the risk of unauthorized access. • Assess the necessity of the ABB Zenon Remote Transport functionality. - Ensure that if the Remote Transport functionality is not used, the zensyssrv.exe (ABB Zenon System Service) is stopped or terminated. The zensyssrv.exe can also be stopped or terminated after authorized use to prevent this vulnerability. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Acknowledgments ABB PSIRT reported this vulnerability to CISA. Notice The information in this document is subject to change without notice, and should not be construed as a commitment by ABB. ABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hard-ware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages. This document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose. All rights to registrations and trademarks reside with their respective owners. Work around • Restrict network access to systems with the ABB zenon Software Platform installed. - Ensure that access to a system is restricted by implementing access controls to minimize the risk of unauthorized access. • Assess the necessity of the ABB Zenon Remote Transport functionality. - Ensure that if the Remote Transport functionality is not used, the zensyssrv.exe (ABB Zenon System Service) is stopped or terminated. The zensyssrv.exe can also be stopped or terminated after authorized use to prevent this vulnerability. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of ABB PSIRT 2NGA002743 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory. Revision History Initial Release Date: 2025-08-12 Date Revision Summary 2025-08-12 1 Initial version. 2026-05-22 2 Minor correction to the affected product version in the product tree. 2026-05-26 3 Initial CISA Republication of ABB PSIRT 2NGA002743 advisory 2026-05-28 4 CISA Republication update based on ABB PSIRT 2NGA002743 advisory. Removed "Trademark" abbreviation from the Ability product name in the title and throughout the advisory. Legal Notice and Terms of Use
· CISA Cybersecurity Advisory

Eppendorf BioFlo 320

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor. The following versions of Eppendorf BioFlo 320 are affected: BioFlo 320 Bioreactor vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.8 Eppendorf Eppendorf BioFlo 320 Use of Hard-coded Password Background Critical Infrastructure Sectors: Healthcare and Public…
Read full source summary
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor. The following versions of Eppendorf BioFlo 320 are affected: BioFlo 320 Bioreactor vers:all/* CVSS Vendor Equipment Vulnerabilities v3 9.8 Eppendorf Eppendorf BioFlo 320 Use of Hard-coded Password Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-7251 The affected product is vulnerable to due to VNC server using a hard-coded password. If a remote attacker knows the network address of any BioFlo 320 model with remote access enabled, they can gain full control of the user interface by using this password. Once connected, the attacker would have full access to all control panel features for the BioFlo 320. VNC traffic is not encrypted. View CVE Details Affected Products Eppendorf BioFlo 320 Vendor: Eppendorf Product Version: Eppendorf BioFlo 320 Bioreactor: vers:all/* Product Status: known_affected Remediations Mitigation Eppendorf has released a software update that permanently removes VNC access from the controller. Users should download and apply this update from: https://www.eppendorf.com/software-downloads. https://www.eppendorf.com/software-downloads Mitigation All affected BioFlo 320 systems always shipped with Virtual Network Computing (VNC) disabled by default, and VNC can only be enabled locally at the tower. Eppendorf has removed VNC configuration information from all current documentation, so it no longer appears in BioFlo 320 Operating Manuals. Mitigation Eppendorf recommends user do the following: Verify that VNC is disabled on the controller Enable security so that only Admin and Supervisor roles can change VNC settings Install Version 5.0 Software as soon as possible Relevant CWE: CWE-259 Use of Hard-coded Password Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Acknowledgments BIO-ISAC reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. Revision History Initial Release Date: 2026-05-26 Date Revision Summary 2026-05-26 1 Initial Publication Legal Notice and Terms of Use
Browse saved snapshots