ics-otregulatorNewsThe Broadside1 min read

ABB patches CVE-2026-31431 in Edgenius industrial gateways

The local-only exploit condition matters less when the affected edge box hosts container workloads inside OT infrastructure.


TL;DR

ABB released Edgenius 3.2.4.1 to fix CVE-2026-31431, a CVSS 7.8 Linux kernel privilege-escalation flaw affecting versions 3.2.0.0 through 3.2.4.0 on bE100, E3100C, and vE1000 systems. Contractors and MSPs supporting critical-manufacturing OT environments should patch exposed Edgenius nodes. ABB says exploitation requires local access or a compromised container workload, which is exactly the detail that keeps this from being a simple perimeter problem.

CISA republished ABB's advisory for CVE-2026-31431, a publicly disclosed Linux kernel flaw in the algif_aead cryptographic interface that can let a locally authenticated user, or a compromised container workload, gain root on affected ABB Ability Edgenius systems. The fix is Edgenius 3.2.4.1. The affected range is Edgenius 3.2.0.0 through 3.2.4.0 on the ABB Ability Edgenius Gateway bE100, Gateway E3100C, and Server vE1000.

The operational risk is easy to understate because the CVSS vector is local: AV:L, PR:L, UI:N, with high confidentiality, integrity, and availability impact. ABB says the issue is not remotely exploitable in the ordinary sense and would require physical access or valid SSH credentials. That is useful, but it is not the end of the analysis for an industrial edge platform that can host applications and container workloads. In shared, containerized, or multi-tenant environments, local code execution is not an exotic scenario. It is part of the threat model.

For contractors and MSPs running or administering Edgenius in critical-manufacturing environments, the Monday task is version inventory and controlled update planning. Confirm whether bE100, E3100C, or vE1000 deployments are running any 3.2.0.x through 3.2.4.0 build, restrict SSH and cockpit access, review lower-privilege local accounts, and test the 3.2.4.1 update against production constraints before rollout. ABB says it had no reports of exploitation against Edgenius when the advisory issued. That is reassuring only until the first foothold lands on the box.


Published ·Deep Fathom