Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600).

This issue affects Protection and control IED manager (PCM600): through 2.14.
Published: 2026-09-28
Score: 5.6 Medium
EPSS: n/a
KEV: No
Impact: Path Traversal
Action: Apply Patch
AI Analysis

Impact

This vulnerability allows an attacker to manipulate the import process of project archives to reference files outside the intended directory, enabling unauthorized reading of arbitrary files on the filesystem. The weakness is a classic Path Traversal flaw categorized as CWE-22, supporting the potential for a confidentiality breach by exposing sensitive data that should be protected by the system’s directory structure.

Affected Systems

ABB Protection and Control IED Manager (PCM600) is affected up to and including version 2.14. Users running any of these versions should verify their installed release and plan an upgrade.

Risk and Exploitability

The CVSS score of 5.6 indicates a moderate severity, and the EPSS score is not available, making it unclear how frequently attempts are made. The vulnerability is not listed in CISA KEV, suggesting no publicly known exploitation. Based on the description, the likely attack vector involves an attacker with the ability to use the project archive import feature—whether through a remote interface or local access—to supply crafted file paths that escape the intended directory.

Generated by OpenCVE AI on September 28, 2026 at 15:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a PCM600 release newer than 2.14 which removes the path traversal flaw.
  • Restrict the import functionality to users with the appropriate privileges and consider disabling the feature if it is not required for business processes.
  • Configure the system to log all import attempts and monitor for unusual file references to detect potential exploitation attempts.

Generated by OpenCVE AI on September 28, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Abb
Abb protection And Control Ied Manager (pcm600)
Vendors & Products Abb
Abb protection And Control Ied Manager (pcm600)

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.
Title Path Traversal During Project Archive Import
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 5.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

Abb Protection And Control Ied Manager (pcm600)
cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2026-09-28T16:32:28.788Z

Reserved: 2026-07-16T13:14:19.501Z

Link: CVE-2026-15953

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:15.283

Modified: 2026-09-28T16:31:16.073

Link: CVE-2026-15953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:22:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')