ics-otregulatorNewsThe Broadside2 min read

CISA flags ABB PCM600 flaws that hand attackers SYSTEM

No patch exists; ABB's only fix is reconfiguring a Windows service so the LocalSystem privilege ladder loses its first rung.


TL;DR

CISA's ICSA-26-274-03 covers two flaws in ABB Protection and Control IED Manager PCM600 versions 2.14 and earlier. CVE-2026-15952 lets a standard local user escalate privileges because the ABBPCMSchedulerService runs as LocalSystem while granting permissions to the local users group (CVSS 3.1 6.4, CVSS 4.0 7.1). CVE-2026-15953 is a path traversal in project-archive extraction that writes files outside the target directory. ABB offers workarounds in advisories 2NGA003170 and 2NGA003179, not a corrected version.

CISA published ICSA-26-274-03 on Oct. 1 covering ABB Protection and Control IED Manager PCM600 2.14 and earlier, deployed worldwide in the energy sector. Two CVEs, both local-access, both aimed at the same box: the engineering workstation that configures protection relays.

The privilege bug is the one to fix

CVE-2026-15952 (CWE-732) is a service permission problem. ABBPCMSchedulerService executes under the LocalSystem account, and permissions on that service are granted to standard PCM600 users through membership in the local users group. Anyone with valid credentials on the host can therefore elevate to SYSTEM and take the machine. CVSS 3.1 scores it 6.4 medium; CVSS 4.0 calls it 7.1 high. The gap matters because 4.0 reflects the actual blast radius: LocalSystem on a host that holds IED credentials and configuration files is full control of substation settings.

ABB's remedy isn't a patch. It's reconfiguring the service to log on as the same Windows account used to run PCM600 rather than LocalSystem, with that account holding the "Log on as a service" privilege. Operators must also ensure the Scheduler tool runs under that same account wherever IED authentication is enabled, and restrict the "Always trust IED security certificates" setting to communications inside a trusted environment. That's three manual configuration changes per installation, none of which corrects the underlying defect.

Same family, fifth advisory

CVE-2026-15953 (CWE-22) sits at 5.0 under CVSS 3.1. Insufficient validation of archive entry paths during PCM600 project file extraction permits writes outside the intended directory. It's Zip-Slip reappearing in a different code path: CISA's 2026 ICSA-26-120-02 advisory flagged a path traversal in the SharpZip.dll bundled with PCM600 1.5 through 2.13, fixed in 2.14. Hitachi Energy's March ICSA-26-125-01 carried the same CVE into its 3.x PCM600 line. And back in 2022, ICSA-22-333-02 documented cleartext IED credential storage in PCM600 2.11 and earlier, exploitable by anyone reading a backup file or database log on the host. PCM600's attack surface is broad, and it keeps being rediscovered rather than designed out.

What this means for Monday

Energy operators with PCM600 2.14 or earlier on engineering workstations should apply ABB's service logon reconfiguration now and treat it as a compensating control with a tracking item, not a closure. Confirm that no patched release has superseded the workaround, then check the related exposure: if an attacker has LocalSystem on the PCM600 host, they have the IED backup files and, on 2.11 and earlier installs, credentials to load incorrect configurations or reboot relays. There is no such thing as patching a relay from here.

CISA reports no known public exploitation of either CVE. Researcher Abhinav Agarwal reported both flaws.


Published ·Deep Fathom