🔥 この記事の詳細
2026-10-01 更新
C
月内に

ABBのProtection and Control IED Manager PCM600(バージョン2.14以下)に、権限昇格およびファイル上書きが可能な脆弱…

脆弱性🌐 英語ソース
🔢 CVECVE-2026-15952CVE-2026-15953
📅 2026-10-01📰 cisa
📌 一言でいうと
ABBのProtection and Control IED Manager PCM600(バージョン2.14以下)に、権限昇格およびファイル上書きが可能な脆弱性が発見されました。攻撃者がローカルアクセス権と有効なユーザー資格情報を保持している場合、不適切な権限割り当てやパストラバーサルを利用して特権を昇格させることが可能です。影響を受ける環境では、最新バージョンへのアップデートが推奨されます。
🔍該当判定
  • ABB製の電力・制御システム管理ソフト『PCM600』を社内で利用している
  • PCM600のバージョンが 2.14 以前である
  • 工場や発電所などの設備制御(IED管理)にABB製品を導入している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受けるPCM600のバージョンを確認し、ベンダーが提供する最新の修正済みバージョンへアップデートしてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】ABB PCM600 権限昇格の脆弱性 (CVE-2026-15952, CVE-2026-15953) 対応について

お疲れさまです。ABB PCM600に関する脆弱性情報共有です。

■ 概要
ABB Protection and Control IED Manager PCM600において、不適切な権限割り当ておよびパストラバーサルの脆弱性が報告されました。CVSS v3 スコアは 6.4 であり、ローカルアクセスを持つ攻撃者が特権昇格やファイルの書き換えを行う可能性があります。

■ 影響範囲
- 対象製品: ABB Protection and Control IED Manager PCM600
- 対象バージョン: 2.14 以下のバージョン

■ 対応手順
1. 自社環境で利用しているPCM600のバージョンを確認してください。
2. 影響を受けるバージョンである場合、ABBの公式サポートを通じて最新バージョンへのアップデートを適用してください。

■ 参考情報
- CISA ICS Advisory (ICSA-26-274-03)

対応優先度: 中
対応期限: 次回メンテナンス時まで
Subject: [Security Advisory] ABB PCM600 Privilege Escalation Vulnerabilities (CVE-2026-15952, CVE-2026-15953)

Dear Team,

We are sharing technical details regarding vulnerabilities found in ABB Protection and Control IED Manager PCM600.

■ Overview
Incorrect permission assignments and path traversal vulnerabilities have been identified in the Scheduler Service of PCM600. With a CVSS v3 score of 6.4, these flaws could allow an attacker with local access and valid credentials to escalate privileges or overwrite critical files.

■ Affected Scope
- Product: ABB Protection and Control IED Manager PCM600
- Versions: 2.14 and earlier

■ Mitigation Steps
1. Verify the installed version of PCM600 in your environment.
2. If an affected version is in use, update to the latest patched version provided by ABB.

■ Reference
- CISA ICS Advisory (ICSA-26-274-03)

Priority: Medium
Deadline: Next scheduled maintenance window