Junglewise Threat Intelligence

CVE-2025-9970: ABB LVS MConfig cleartext storage of sensitive information in memory

CVE-2025-9970 · Severity: high · CVSS 7.4 · Published 2026-05-26

Vendors: ABB.

Executive brief

ABB LVS MConfig is a software tool used to configure and manage low-voltage switchgear components in industrial environments. A vulnerability in this software could allow an attacker with physical or local access to the computer running the application to extract sensitive user credentials from the system's memory. If successful, an attacker could use these credentials to modify critical equipment settings, potentially disrupting power distribution or damaging industrial hardware.

Technical details

A vulnerability classified as CWE-316 (Cleartext Storage of Sensitive Information in Memory) exists in ABB LVS MConfig versions 1.4.9.21 and prior. The application fails to properly clear or encrypt authentication-related data in memory after a user logs in. An attacker with local access to the host operating system can generate a memory dump of the running process and extract plain-text passwords. Exploitation requires the attacker to have local access and for a legitimate user to be logged into the application. Once credentials are recovered, the attacker could potentially modify the configuration of motor controllers, operation panels, and protocol converters. The issue is resolved in version 1.4.9.22 by implementing SHA-256 hashing and ensuring memory is cleared after authentication.

Affected products

  • ABB LVS MConfig <=1.4.9.21

Timeline

  • 2026-05-26: advisory: CISA and ABB published the advisory.

References