Junglewise Threat Intelligence

CVE-2025-3756: ABB Multiple Products denial of service in IEC 61850 stack

CVE-2025-3756 · Severity: high · CVSS 6.5 · Published 2026-04-13

Vendors: ABB.

Executive brief

A vulnerability in ABB industrial control system components can allow an attacker to disrupt communications between power grid or industrial devices. By sending a malicious network packet, an attacker could force specific communication modules into a fault state, leading to a loss of monitoring and control capabilities for those specific segments. While the overall operation of the management node remains functional, the loss of real-time data from the field devices could impact operational visibility.

Technical details

The vulnerability is located in the command handling logic of the IEC 61850 communication stack (CWE-1284). An attacker with access to the adjacent IEC 61850 network can exploit this by sending a specially crafted packet to the target device. Successful exploitation forces the PM 877, CI850, and CI868 modules into a fault mode or causes the S+ Operations 61850 connectivity to become unavailable. This results in a denial-of-service (DoS) condition specifically for the 61850 communication function, though the broader S+ Operations node functionality remains intact.

Affected products

  • ABB AC800M (System 800xA) 6.0.0x through 6.0.0303.0, 6.1.0x through 6.1.0031.0, 6.1.1x through 6.1.1004.0, 6.1.1x through 6.1.1202.0, 6.2.0x through 6.2.0006.0
  • ABB Symphony Plus SD Series A_0, A_1, A_2.003, A_3.005, A_4.001, B_0.005
  • ABB Symphony Plus MR (Melody Rack) 3.10 through 3.52
  • ABB S+ Operations 2.1, 2.2, 2.3, 3.3

Timeline

  • 2026-04-13: disclosed
  • 2026-04-13: advisory

References