ics-otregulatorNewsThe Broadside1 min read

CISA flags four ABB T-MAC Plus flaws

Authenticated users on affected industrial networks can reach file disclosure, privilege escalation and authorization-bypass paths before the 4.0-25 fix lands.


TL;DR

CISA published an advisory for four vulnerabilities, CVE-2025-14771 through CVE-2025-14774, in ABB T-MAC Plus 4.0-24. ABB says version 4.0-25 corrects the issues. The highest score is CVSS 9.9, with impacts including sensitive file exfiltration, administrative operations by low-privilege users, stored XSS and a Card Reader service denial of service.

Organizations running ABB T-MAC Plus 4.0-24 should move to version 4.0-25 and verify the update is actually available in their deployment channel. CISA’s advisory covers four flaws in a product deployed worldwide in critical manufacturing: file disclosure through crafted HTTP GET requests, broken access controls that let low-privilege users perform administrative operations, stored cross-site scripting and an insecure network protocol that can block the Card Reader service until manual restart. Most of the serious paths require authentication or access to the operations network, which is not comfort in an industrial control system. It is the boundary the attacker tries to get across first.


Published ·Deep Fathom