Executive brief
ibaPDA and ibaDatCoordinator are industrial data acquisition and management tools used to monitor and process process data. A security vulnerability allows an unauthorized person to remotely take full control of the systems running this software. This could lead to the theft of sensitive industrial data, disruption of monitoring operations, or unauthorized changes to system configurations.
Technical details
A deserialization vulnerability (CWE-502) exists in ibaPDA and ibaDatCoordinator due to improper restriction of the .NET BinaryFormatter when processing client-server input. A remote, unauthenticated attacker can exploit this by sending specially crafted data to the application, leading to type confusion and arbitrary code execution. The code executes with the privileges of the service user account, potentially allowing for full system compromise. The vulnerability is addressed in ibaPDA version 8.14.0 and ibaDatCoordinator version 4.0.7. Temporary mitigations include restricting network access via Windows Firewall rules to localhost or specific trusted ports.
Affected products
- iba AG ibaPDA >=1.0.0, <8.14.0
- iba AG ibaDatCoordinator >=1.0.0, <4.0.7
Timeline
- 2026-06-17: advisory: Initial advisory published by CERT@VDE
- 2026-06-18: disclosed: CVE published to NVD dataset