← Back to home
ICSA-26-132-05  ·  Published 2026-05-12  ·  View on CISA ICS-CERT ↗

ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax

CVSS 9.8 CRITICAL

Risk Summary

ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves publicly reported vulnerability. An attacker who successfully exploited these vulnerabilities could cause a crash, denial-of-service (DoS), or potentially remote code execution.

CVEs (1)

Remediations

  • The problem is corrected in the following product version: - AC500 V3 firmware version 3.9.0 HF1 ABB recommends that customers apply the update at earliest convenience. This firmware version is released for all AC500 V3 PLC types and available for download from the ABB library. https://search.abb.com/library/Download.aspx?DocumentID=3ADR011537&LanguageCode=en&DocumentPartId=&Action=Launch
  • Refer to section “General security recommendations” for further advise on how to keep your system secure.
  • No workarounds are available

Affected Vendors

ABB

Affected Products (2)

ABB · AC500 V3 Firmware 3.9.0
ABB · AC500 V3 Firmware 3.9.0_HF1

Affected Sectors

Chemical, Critical Manufacturing, Energy, Water and Wastewater

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more