As reported by CISA in advisory ICSA-26-274-03, ABB's Protection and Control IED Manager PCM600 contains two vulnerabilities that collectively enable local privilege escalation and arbitrary file overwrite on affected engineering workstations. While the CVSS v3 score of 6.4 (Medium) may seem modest, Shield53 assesses the operational risk as elevated for energy-sector operators who rely on PCM600 to manage intelligent electronic devices across substation environments.
Why This Matters More Than the Score Suggests
The vulnerability class here — incorrect permission assignment on a service running as LocalSystem — is a textbook OT weakness. The Scheduler Service inherits full system-level privileges, yet its permissions are delegated to standard users via the local Users group. In environments where engineering workstations are shared among shift teams or contractors, any compromised user credential becomes a bridge to full host compromise. Once an attacker holds SYSTEM on an engineering workstation, they can pivot to IED configuration manipulation, certificate theft, or lateral movement into the broader OT network.
The path traversal component (CVE-2026-15953) compounds this by enabling file overwrite outside intended directories, which could be leveraged to plant malicious binaries, corrupt configuration files, or modify startup scripts.
Vulnerability Summary
| CVE | CVSS v3 | Type | Impact | Patch Available? | In-the-Wild Exploitation |
|---|---|---|---|---|---|
| CVE-2026-15952 | 6.4 (Medium) | Incorrect Permission Assignment for Critical Resource | Local privilege escalation to SYSTEM | No — workaround only | Not reported |
| CVE-2026-15953 | 6.4 (Medium) | Path Traversal | Arbitrary file overwrite | No — workaround only | Not reported |
Affected Product: ABB Protection and Control IED Manager PCM600, versions Critical Infrastructure Sector: Energy (substation protection and control)Deployment: WorldwideVendor: ABB (Switzerland)
Who Is Most Exposed
Shield53 identifies the following deployment profiles as highest risk:
- Shared engineering workstations in substations or control rooms where multiple operators share credentials or use generic accounts
- Contractor-accessible PCM600 installations where third-party integrators have local user accounts on the same host
- Air-gapped or semi-isolated OT networks where patching cycles are slow and the workaround is the only immediate defense
- Deployments where IED authentication is disabled or where the "Always trust IED security certificates" setting is enabled in untrusted network segments
The absence of a firmware or software patch is notable. ABB's workaround — reconfiguring the ABBPCMSchedulerService to run under the same account used for PCM600 operation — is effective but operationally disruptive. It fundamentally changes how the scheduler interacts with IED communication and certificate handling, and must be validated against each site's authentication architecture before deployment.
Shield53 Recommendations
Immediate Actions:
- Inventory and identify all PCM600 installations across your OT estate, including version numbers and host operating systems. Prioritize hosts where multiple users share local accounts.
- Apply the ABB workaround on non-critical hosts first: reconfigure the ABBPCMSchedulerService logon account via Services.msc to match the PCM600 operator account. Ensure that account has "Log on as a service" rights.
- Restrict local user group membership on PCM600 workstations. Remove generic or contractor accounts that do not require interactive login. Enforce individual, named accounts with audit logging.
- Disable "Always trust IED security certificates" in PCM600 settings unless communication occurs within a verified secure segment. This reduces the attack surface for MITM-based certificate abuse.
- Deploy endpoint detection rules for anomalous child processes spawned by ABBPCMSchedulerService or unexpected file writes outside the PCM600 installation directory. Monitor for attempts to modify the service's Log On configuration.
- Network segmentation — ensure PCM600 workstations are not reachable from IT-side or internet-facing systems. The vulnerability requires local access, so limiting who can reach the host is your primary preventive control.
- Engage ABB support to request a formal patch timeline. Track this advisory and escalate through your vendor risk management process if a fix is not delivered within 90 days.
Shield53 will continue monitoring this advisory for patch availability and any emergence of active exploitation. Given the energy-sector deployment profile and the current geopolitical emphasis on critical infrastructure targeting, we assess the likelihood of targeted exploitation as moderate but rising if PoC details circulate.