Critical CVE‑2025‑14771‑14774 in ABB T‑MAC Plus (Industrial Control System) Threatens Manufacturing Operations
What It Is — ABB disclosed four critical vulnerabilities (CVE‑2025‑14771 to 14774) affecting the T‑MAC Plus 4.0‑24 control‑system firmware. The flaws include file disclosure, authorization bypass, cross‑site scripting, and improper input handling, each rated CVSS v3 9.9.
Exploitability — Public advisory indicates an attacker with network access could craft HTTP requests to exfiltrate files or gain unauthorized control. No public exploit code has been released, but the severity and CVSS score suggest a low barrier for a motivated adversary.
Affected Products — ABB T‑MAC Plus 4.0‑24 (industrial automation controller used in critical manufacturing).
Why It Matters for Compliance & Audit Readiness
- Vendor‑risk monitoring – SOC 2 requires documented due‑diligence on third‑party hardware; tracking ABB advisories and patch status satisfies CC6.1 (risk mitigation) and CC7.1 (monitoring).
- Continuous evidence – Capturing remediation timestamps and patch‑level inventory provides audit‑ready evidence of control effectiveness.
- Control mapping – The vulnerabilities map to SOC 2 security principles (access control, change management, and system operations), so remediation must be reflected in your control matrix.
Recommended Actions
- Inventory all ABB T‑MAC Plus devices and verify firmware version.
- Apply ABB’s remediation update immediately; document the patch rollout.
- Update your vendor‑risk dashboard with the advisory, remediation status, and risk rating.
- Map the fix to SOC 2 controls (e.g., CC6.1, CC7.1) and retain evidence for the next audit.
Source: CISA Advisory – ICSA‑26‑195‑03