Privilege Escalation & Path‑Traversal in ABB Protection & Control IED Manager PCM600 (CVE‑2026‑15952, CVE‑2026‑15953)
What It Is – Two critical flaws were disclosed in ABB’s IED Manager PCM600 (versions ≤ 2.14). CVE‑2026‑15952 is an incorrect permission assignment that lets a standard user elevate to LocalSystem. CVE‑2026‑15953 is a path‑traversal flaw that can be used to overwrite arbitrary files.
Exploitability – Both vulnerabilities have a CVSS v3.1 base score of 6.4 (moderate). Exploits require a valid local user account; no public exploit code is known, but the attack surface is realistic for on‑site operators or compromised insider credentials.
Affected Products – ABB Protection and Control IED Manager PCM600, all releases up to version 2.14.
Why It Matters for Trust & Control Assurance
- Access‑control hygiene – The privilege‑escalation flaw shows why strict separation of duties and least‑privilege assignments are essential control objectives.
- Evidence of remediation – Demonstrating that the vulnerability is patched (or mitigated) provides concrete audit evidence for regulators and customers demanding continuous assurance.
- Defensible incident response – Knowing the exact vector (local service running as LocalSystem) enables focused monitoring and rapid containment, reinforcing a trustworthy security posture.
Recommended Actions
- Apply ABB’s latest firmware release (≥ 2.15) that resolves CVE‑2026‑15952 and CVE‑2026‑15953.
- If immediate patching is not possible, implement the vendor‑provided workaround: restrict Scheduler Service execution to a dedicated, non‑privileged account and enforce file‑system ACLs that block unauthorized path traversal.
- Review and tighten local user group memberships on all PCM600 hosts; enforce least‑privilege principles.
- Enable logging of privileged service starts and file‑write events; forward logs to a centralized SIEM for continuous monitoring.
- Capture remediation evidence (patch logs, configuration snapshots) for audit readiness.
Source: CISA Advisory – ICSA‑26‑274‑03