Sceawere

Vulnerability Detail

CVE-2026-15953UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Path Traversal in ABB PCM600

Vulnerability Metadata

Severity
Medium
Score / CVSS
5
Creation Date
3h ago
Vendor
ABB
Product
Protection and control IED manager (PCM600)
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.0",
  "pubDate": "2026-09-28T14:17:15.283Z",
  "pubdate": "2026-09-28T14:17:15.283Z",
  "executiveSummary": "This vulnerability is an Improper Limitation of a Pathname to a Restricted Directory, commonly known as Path Traversal (CWE-22), identified in ABB Protection and control IED manager (PCM600). The flaw exists in versions through 2.14.\nThe vulnerability allows an unauthenticated or low-privileged attacker to manipulate file paths, potentially leading to unauthorized file system access. By crafting malicious input containing directory traversal sequences (e.g., ../), an attacker can bypass intended security constraints to read or overwrite sensitive files outside the designated directory structure.\nThe impact includes potential information disclosure of sensitive system files, configuration data, or project files managed by the IED manager. In certain scenarios, this may lead to further exploitation, such as remote code execution or complete system compromise, depending on the file types accessible and the permissions of the application process.\nThe risk is significant for industrial control system (ICS) environments where PCM600 is deployed, as successful exploitation could lead to loss of confidentiality, integrity, and availability of critical protection and control engineering tasks.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient validation and sanitization of user-supplied input used to construct file system paths within the PCM600 application. When the application handles file operations—such as importing, exporting, or loading project-related files—it fails to properly neutralize directory traversal sequences (e.g., '../' or '..\\') provided in file names or path parameters.\nThis failure allows an attacker to 'break out' of the intended directory context assigned to the application. The vulnerable component processes the tainted input as a legitimate path, causing the underlying operating system to resolve the path to locations outside the restricted sandbox or application data folder.\nThe attack flow typically involves an attacker intercepting or manipulating requests that involve file handling operations within the PCM600 interface. By injecting sequences like '../../' into a filename parameter, the attacker forces the application to reference a file at a different absolute or relative path.\nIf the application runs with elevated privileges—common for software managing industrial IEDs—the resulting file access will occur with those same privileges. This could allow an attacker to read configuration files containing credentials, internal topology maps, or system keys. Furthermore, if the vulnerability allows for write operations, an attacker might overwrite critical application binaries or configuration files, potentially leading to arbitrary code execution upon subsequent application startup.\nThe affected versions are all iterations of Protection and control IED manager (PCM600) up to and including version 2.14. The vulnerability is triggered by providing malicious input to application functions responsible for file system interactions, which may not require complex authentication if the affected interface is exposed on the network or via local project files.\nPost-exploitation impact includes persistent control over the project engineering environment, potential modification of IED configuration files leading to operational disruption, and the exfiltration of sensitive site-specific protection logic and network configurations."
}
CVE-2026-15953: Path Traversal in ABB PCM600 (MEDIUM Severity, CVSS: 5.0) | Sceawere