Impact
This vulnerability allows an attacker to manipulate the import process of project archives to reference files outside the intended directory, enabling unauthorized reading of arbitrary files on the filesystem. The weakness is a classic Path Traversal flaw categorized as CWE-22, supporting the potential for a confidentiality breach by exposing sensitive data that should be protected by the system’s directory structure.
Affected Systems
ABB Protection and Control IED Manager (PCM600) is affected up to and including version 2.14. Users running any of these versions should verify their installed release and plan an upgrade.
Risk and Exploitability
The CVSS score of 5.6 indicates a moderate severity, and the EPSS score is not available, making it unclear how frequently attempts are made. The vulnerability is not listed in CISA KEV, suggesting no publicly known exploitation. Based on the description, the likely attack vector involves an attacker with the ability to use the project archive import feature—whether through a remote interface or local access—to supply crafted file paths that escape the intended directory.
OpenCVE Enrichment