Cleartext Storage of Sensitive Information Vulnerability in ABB MConfig
CVE-2025-9970

5.7MEDIUM

Key Information:

Vendor

Abb

Status
Vendor
CVE Published:
8 October 2025

What is CVE-2025-9970?

The ABB MConfig software exhibits a vulnerability that allows the cleartext storage of sensitive information in memory. This flaw poses a risk to data confidentiality and integrity, particularly if malicious actors gain access to this stored information. Users of MConfig versions 1.4.9.21 and earlier should be aware of this risk and consider implementing best practices for data protection to mitigate the potential impacts.

Affected Version(s)

MConfig 0 <= 1.4.9.21

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9970 : Cleartext Storage of Sensitive Information Vulnerability in ABB MConfig