[ABB Protection and Control IED Manager PCM600]: ABB PCM600 CISA Advisory: Affected Versions, Operator Checks, and Scheduler Service Risk

Macro photograph of the Book of Jonah page in a Bible, highlighting text and typography.

Which ABB PCM600 versions are affected by the October 1, 2026 CISA advisory?

Macro photograph of the Book of Jonah page in a Bible, highlighting text and typography.

CISA’s October 1, 2026 ICS advisory identifies ABB Protection and Control IED Manager PCM600 as the affected product.

Affected versions

The affected versions are:

Product Affected versions
ABB Protection and Control IED Manager PCM600 PCM600 2.14 and earlier

If you operate PCM600, the first check is whether your installed version is 2.14 or older.

What CISA says the risk involves

The advisory says exploitation could allow an attacker to raise privileges or overwrite files. It also lists the Energy sector as affected, with deployments worldwide.

One listed issue involves the PCM600 Scheduler Service running as LocalSystem while standard PCM600 users have permissions through the local users group.

What is not included here

The provided context does not include patch instructions, mitigation steps, or version-specific upgrade guidance. Before making operational changes, check the CISA advisory and ABB’s official guidance for current instructions.

What should energy-sector operators check in ABB PCM600 after the CISA advisory?

Minimalist photo of scrabble tiles spelling 'DO WHAT YOU LOVE' on a white background.

Energy-sector operators using ABB PCM600 should start with a narrow check: whether their deployment is running PCM600 2.14 or earlier.

Checks to prioritize

Based on the advisory details provided, operators should confirm:

  • whether ABB Protection and Control IED Manager PCM600 is deployed
  • whether the version is PCM600 2.14 or earlier
  • whether the deployment is part of an Energy-sector environment
  • whether standard PCM600 users have local users group permissions
  • whether the PCM600 Scheduler Service configuration matches the advisory concern

The context says the Scheduler Service issue involves the service running as LocalSystem while standard PCM600 users have permissions through the local users group.

Why those checks matter

CISA said exploitation could let an attacker raise privileges or overwrite files. That makes user permissions and service privilege level central to understanding exposure.

The advisory also says deployments are worldwide, so the issue is not limited to one country or region in the provided summary.

Use the official advisory for next steps

The context does not provide remediation commands, patch versions, or compensating controls. Treat the CISA advisory as the source to review before deciding on changes in an operational environment.

What changes in risk does the PCM600 Scheduler Service vulnerability create for standard users?

Close-up of a person writing a lunch reminder on an October calendar with a purple pen.

The Scheduler Service issue changes the risk around standard PCM600 users because the service runs as LocalSystem while those users have permissions through the local users group.

The risk change in plain terms

LocalSystem is a highly privileged service context. The context says standard PCM600 users have permissions through the local users group, while the PCM600 Scheduler Service runs as LocalSystem.

CISA said exploitation could allow privilege escalation or file overwrite. In practical review terms, that means standard-user access should not be treated as low-impact without checking the advisory details.

What operators should examine

The provided facts point to three areas to review:

Area Why it matters
PCM600 version PCM600 2.14 and earlier are affected
Scheduler Service The issue involves LocalSystem execution
Standard user permissions The advisory highlights local users group permissions

What is not confirmed here

The context does not say which specific actions a standard user could perform, whether exploitation requires local access, or what patch level resolves the issue. Use CISA’s advisory and vendor guidance for those details.

Sources / Learn more

Related reading

Comments

Leave a Reply

[privacy-do-not-sell-link]

Discover more from Trending Issues Daily

Subscribe now to keep reading and get access to the full archive.

Continue reading