Stack-based Buffer Overflow in ABB RMC-100 and RMC-100 LITE
CVE-2025-6072
8.2HIGH
What is CVE-2025-6072?
A stack-based buffer overflow vulnerability exists in ABB's RMC-100 and RMC-100 LITE products. When the REST interface is enabled, an attacker on the control network can exploit this flaw by injecting specially crafted JSON configuration data. This exploitation allows the attacker to overflow the date of expiration field, potentially compromising the integrity and functionality of the affected devices. The vulnerability specifically impacts RMC-100 units from versions 2105457-043 to 2105457-045 and RMC-100 LITE units from versions 2106229-015 to 2106229-016.
Affected Version(s)
RMC-100 2105457-043 <= 2105457-045
RMC-100 LITE 2106229-015 <= 2106229-016
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ABB thanks Claroty Team82 Research for helping to identify the vulnerabilities and protecting our customers