Executive brief
ABB T-MAC Plus, a system used for building automation and energy management, contains a vulnerability that allows unauthorized access to internal files and directories. An attacker could exploit this to view sensitive configuration data, modify system settings, or disrupt operations. This could lead to a total loss of confidentiality and control over the affected building management infrastructure.
Technical details
A vulnerability classified as CWE-552 (Files or Directories Accessible to External Parties) exists in ABB T-MAC Plus version 4.0-24. The flaw allows an authenticated user with low privileges to access sensitive files or directories that should be restricted. Because the CVSS vector indicates a 'Scope Change' (S:C), the impact extends beyond the immediate application to the underlying host or connected systems. An attacker can leverage this access to achieve full confidentiality, integrity, and availability impact (C:H/I:H/A:H) over the network without user interaction.
Affected products
- ABB T-MAC Plus 4.0-24
Timeline
- 2026-06-03: advisory: Initial disclosure by ABB and NVD publication.