Sceawere
Vulnerability Detail
CVE-2026-15952UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
PCM600 Incorrect Resource Permission Assignment
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 3h ago
- Vendor
- ABB
- Product
- Protection and control IED manager (PCM600)
- Attack Type
- CWE-732 Incorrect Permission Assignment for Critical Resource
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-09-28T14:17:15.110Z",
"pubdate": "2026-09-28T14:17:15.110Z",
"executiveSummary": "This vulnerability involves an Incorrect Permission Assignment for Critical Resource within the ABB Protection and control IED manager (PCM600), specifically affecting versions through 2.14.\nThe flaw allows unauthorized users to interact with or modify sensitive system resources that should be restricted based on security policy.\nThe vulnerability is classified under CWE-732: Incorrect Permission Assignment for Critical Resource, indicating that the application fails to properly implement access control mechanisms on files, directories, or registry keys.\nThe impact includes potential unauthorized modification of configuration data, exposure of sensitive internal information, or loss of control over the IED management process.\nAn attacker with local or network access to the workstation running PCM600 could leverage this deficiency to gain unauthorized read or write access to protected assets, potentially leading to a compromise of the integrity and confidentiality of the protection and control infrastructure.\nThis vulnerability represents a significant risk to industrial control environments where PCM600 is deployed, necessitating timely assessment and hardening of the host workstation.",
"technicalDetails": "The vulnerability stems from improper access control configuration during the installation or runtime operation of ABB PCM600 versions through 2.14. The application environment fails to enforce restrictive OS-level permissions (such as NTFS ACLs or file system object access rights) on critical resources, such as configuration databases, project files, or logging directories.\nBecause the application does not explicitly restrict access to these critical objects, any user or process with authenticated access to the host operating system may gain unauthorized interaction capabilities. In multi-user or shared-workstation environments, this allows for privilege escalation or unauthorized data manipulation, circumventing the intended security model of the PCM600 software.\nThe attack flow typically begins with an actor identifying the insufficiently protected file paths or registry hives associated with the PCM600 installation. By bypassing standard application-level authentication, the attacker directly interacts with the underlying resources. For instance, if an attacker gains read access to project configuration files, they could extract sensitive information such as device credentials, communication parameters, or network topology details.\nFurthermore, write access to these resources allows for the modification of protection relay configurations. By altering parameter files or project settings while the application is idle or offline, an attacker could potentially inject malicious configurations that take effect upon the next synchronization with the actual IED (Intelligent Electronic Device).\nThe exploitation does not necessarily require advanced network-level exploits; rather, it exploits the failure to adhere to the principle of least privilege at the host operating system level. The vulnerable component is the local file system or registry management implementation within PCM600 that neglects to apply adequate access control lists (ACLs) during resource creation. The post-exploitation impact includes the potential to disrupt industrial operations, alter protective relay logic, or exfiltrate configuration data critical to the power system infrastructure, thereby undermining the security posture of the managed electrical grid components."
}