WORLDTECH NEWS Global technology intelligence.Contact
โ† Back to WORLDTECH

ABB Protection and Control IED Manager PCM600

Padlock on the floor of a server room beside cabled switchesAI illustration
WORLDTECH illustration ยท AI-generated (Canva)

What happened

An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group.

View CVE Details Affected Products ABB Protection and Control IED Manager PCM600 Vendor: ABB Product Version: ABB Protection and Control IED Manager PCM600: < =2.14 Product Status: known_affected Remediations Mitigation ABB recommends the following workaround. Although this workaround does not correct the underlying vulnerability, it reduces the risk of privilege escalation (gaining powers on a system that the user was not given).

Mitigation Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600: Open Services.msc. Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version.

Sources & evidence