Executive brief
A vulnerability in ABB industrial control system components can allow an attacker to disrupt communications between power grid or industrial devices. By sending a malicious network packet, an attacker could force specific communication modules into a fault state, leading to a loss of monitoring and control capabilities for those specific segments. While the overall operation of the management node remains functional, the loss of real-time data from the field devices could impact operational visibility.
Technical details
The vulnerability is located in the command handling logic of the IEC 61850 communication stack (CWE-1284). An attacker with access to the adjacent IEC 61850 network can exploit this by sending a specially crafted packet to the target device. Successful exploitation forces the PM 877, CI850, and CI868 modules into a fault mode or causes the S+ Operations 61850 connectivity to become unavailable. This results in a denial-of-service (DoS) condition specifically for the 61850 communication function, though the broader S+ Operations node functionality remains intact.
Affected products
- ABB AC800M (System 800xA) 6.0.0x through 6.0.0303.0, 6.1.0x through 6.1.0031.0, 6.1.1x through 6.1.1004.0, 6.1.1x through 6.1.1202.0, 6.2.0x through 6.2.0006.0
- ABB Symphony Plus SD Series A_0, A_1, A_2.003, A_3.005, A_4.001, B_0.005
- ABB Symphony Plus MR (Melody Rack) 3.10 through 3.52
- ABB S+ Operations 2.1, 2.2, 2.3, 3.3
Timeline
- 2026-04-13: disclosed
- 2026-04-13: advisory