Cybersecurity · 65 views
ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax
View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability.
AI Summary
ABB disclosed a stack‑buffer overflow vulnerability (CVE‑2025‑15467) in its AC500 V3 controllers, specifically in versions 3.9.0 and 3.9.0_HF1. The flaw occurs when parsing CMS AuthEnvelopedData structures that use AEAD ciphers such as AES‑GCM; the initialization vector from ASN.1 parameters is copied into a fixed‑size stack buffer without length validation. Exploitation could cause a crash, denial‑of‑service, or potentially allow remote code execution. The vulnerability affects critical infrastructure sectors including chemical, manufacturing, energy, and water/wastewater worldwide. ABB has released an update that resolves the publicly reported issue.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- Rogue external MFA providers can steal passwords during loginsContinue reading
- Relays Are Masking Chinese Access to Frontier AI Models in the USContinue reading
- Chinese hackers exploit WordPress, Zyxel flaws to steal govt dataContinue reading
- Microsoft Disrupts EvilTokens Device Code Phishing ServiceContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow