<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T09:48:29.908897+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/2nga003170</id>
    <title>2NGA003170 — ABB Protection and Control IED Manager PCM600 Scheduler Service Privilege Escalation Vulnerability</title>
    <updated>2026-10-02T09:48:29.912135+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>ABB is aware of a reported vulnerability in ABB Protection and Control IED Manager (PCM600).</p>
<p>A local authenticated user belonging to the PCM600 user group may be able to modify the configuration of a Windows service running with SYSTEM privileges. Successful exploitation could allow an attacker to execute arbitrary commands with elevated privileges on the affected workstation.</p>
<p>Note: This document references the ABBPCMSchedulerService_v214 component as implemented in PCM600 version 2.14. However, the described issue is not version-specific and applies equally to the corresponding component in other supported versions of PCM600.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/2nga003170"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-377782</id>
    <title>EUVD-2026-377782</title>
    <updated>2026-10-02T09:48:29.912183+00:00</updated>
    <content>EUVD-2026-377782</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-377782"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-15952</id>
    <title>fkie_cve-2026-15952</title>
    <updated>2026-10-02T09:48:29.912199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600).</p>
<p>This issue affects Protection and control IED manager (PCM600): through 2.14.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-15952"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xfjh-6447-rv2j</id>
    <title>GHSA-xfjh-6447-rv2j</title>
    <updated>2026-10-02T09:48:29.912221+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600).</p>
<p>This issue affects Protection and control IED manager (PCM600): through 2.14.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xfjh-6447-rv2j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsa-26-274-03</id>
    <title>ICSA-26-274-03 — ABB Protection and Control IED Manager PCM600</title>
    <updated>2026-10-02T09:48:29.912236+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host. A vulnerability exists in the processing of PCM600 project archives files. Insufficient validation of archive entry paths may permit path traversal during extraction, potentially allowing files to be written to loca tions outside the intended extraction directory.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsa-26-274-03"/>
  </entry>
</feed>
