Executive brief
ABB PCM600 is a software tool used to configure and manage protection and control devices in power systems and manufacturing plants. A vulnerability in a third-party library used by this software could allow an attacker to execute unauthorized code on the system. This could lead to the modification of device configurations or disruption of industrial operations, though it requires a user to interact with a malicious file.
Technical details
A path traversal vulnerability (CWE-22) exists in the SharpZip.dll library bundled with ABB PCM600 versions 1.5 through 2.13. The flaw allows an attacker to bypass directory restrictions when the software processes specially crafted archive files or messages. Successful exploitation requires a local attacker to convince a user to open a malicious file (User Interaction) and involves high attack complexity. If exploited, the attacker can achieve arbitrary code execution on the host system. ABB has released PCM600 version 2.14 to address this issue, though some legacy protection relays (RE_630) are incompatible with the fix and require system-level mitigations.
Affected products
- ABB PCM600 1.5 to 2.13
Timeline
- 2026-04-30: advisory: Initial CISA advisory release
- 2026-04-30: patched: PCM600 version 2.14 released to fix the issue