Executive brief
ABB AC500 V2 programmable logic controllers (PLCs), which are used to automate industrial processes in sectors like manufacturing and energy, are affected by a data leakage vulnerability. An attacker can send specially crafted network requests to the device to view fragments of previous communications. This could lead to the exposure of sensitive operational data or technical information about the industrial control environment.
Technical details
A buffer over-read vulnerability (CWE-126) exists in the Modbus server component of ABB AC500 V2 PLCs. The flaw is triggered when the device receives unsupported Modbus function codes, causing the server to generate invalid responses that append fragments of previous Modbus telegrams stored in memory. An unauthenticated attacker with network access to the Modbus server can exploit this to leak sensitive data from the PLC's communication history. The issue is resolved in AC500 V2 firmware version 2.5.3 and later.
Affected products
- ABB AC500 V2 <= 2.5.2
Timeline
- 2025-07-23: disclosed: Initial vendor advisory release
- 2026-05-26: advisory: CISA republication of advisory ICSA-26-146-02