Path Traversal Vulnerability in ABB Protection and Control IED Manager
CVE-2026-15953

5.6MEDIUM

Key Information:

Vendor

Abb

Vendor
CVE Published:
28 September 2026

What is CVE-2026-15953?

A Path Traversal vulnerability exists in ABB's Protection and Control IED Manager (PCM600) that allows unauthorized access to restricted directories. When a malicious actor exploits this vulnerability, they can traverse the filesystem and access sensitive data or execute unauthorized commands. This flaw underscores the importance of securing directory access to prevent unauthorized exploitation of system vulnerabilities.

Affected Version(s)

Protection and control IED manager (PCM600) 0 <= 2.14

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.