<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 09:47:44 +0000</lastBuildDate>
    <item>
      <title>2NGA003170 — ABB Protection and Control IED Manager PCM600 Scheduler Service Privilege Escalation Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/2nga003170</link>
      <description>&lt;p&gt;ABB is aware of a reported vulnerability in ABB Protection and Control IED Manager (PCM600).&lt;/p&gt;
&lt;p&gt;A local authenticated user belonging to the PCM600 user group may be able to modify the configuration of a Windows service running with SYSTEM privileges. Successful exploitation could allow an attacker to execute arbitrary commands with elevated privileges on the affected workstation.&lt;/p&gt;
&lt;p&gt;Note: This document references the ABBPCMSchedulerService_v214 component as implemented in PCM600 version 2.14. However, the described issue is not version-specific and applies equally to the corresponding component in other supported versions of PCM600.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ABB is aware of a reported vulnerability in ABB Protection and Control IED Manager (PCM600).&lt;/p&gt;
&lt;p&gt;A local authenticated user belonging to the PCM600 user group may be able to modify the configuration of a Windows service running with SYSTEM privileges. Successful exploitation could allow an attacker to execute arbitrary commands with elevated privileges on the affected workstation.&lt;/p&gt;
&lt;p&gt;Note: This document references the ABBPCMSchedulerService_v214 component as implemented in PCM600 version 2.14. However, the described issue is not version-specific and applies equally to the corresponding component in other supported versions of PCM600.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/2nga003170</guid>
    </item>
    <item>
      <title>EUVD-2026-377782</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-377782</link>
      <description>EUVD-2026-377782</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-377782</guid>
    </item>
    <item>
      <title>fkie_cve-2026-15952</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-15952</link>
      <description>&lt;p&gt;Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600).&lt;/p&gt;
&lt;p&gt;This issue affects Protection and control IED manager (PCM600): through 2.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600).&lt;/p&gt;
&lt;p&gt;This issue affects Protection and control IED manager (PCM600): through 2.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-15952</guid>
    </item>
    <item>
      <title>GHSA-xfjh-6447-rv2j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xfjh-6447-rv2j</link>
      <description>&lt;p&gt;Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600).&lt;/p&gt;
&lt;p&gt;This issue affects Protection and control IED manager (PCM600): through 2.14.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600).&lt;/p&gt;
&lt;p&gt;This issue affects Protection and control IED manager (PCM600): through 2.14.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xfjh-6447-rv2j</guid>
    </item>
    <item>
      <title>ICSA-26-274-03 — ABB Protection and Control IED Manager PCM600</title>
      <link>https://cve.radiocsirt.org/vuln/icsa-26-274-03</link>
      <description>&lt;p&gt;A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host. A vulnerability exists in the processing of PCM600 project archives files. Insufficient validation of archive entry paths may permit path traversal during extraction, potentially allowing files to be written to loca tions outside the intended extraction directory.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host. A vulnerability exists in the processing of PCM600 project archives files. Insufficient validation of archive entry paths may permit path traversal during extraction, potentially allowing files to be written to loca tions outside the intended extraction directory.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsa-26-274-03</guid>
    </item>
  </channel>
</rss>
