The vendor explicitly identifies these products as affected by this CVE.
- ABB Firmware <=6.0.0303.0 (AC800M version 6.0.0-x) installed on ABB AC800M Product line (System 800xA) CI868 for IEC 61850 communication
- ABB Firmware <=1.0031.0 (AC800M version 6.1.0-x) installed on ABB AC800M Product line (System 800xA) CI868 for IEC 61850 communication
- ABB Firmware <=6.1.1004.0 AC800M version 6.1.1-0 and 6.1.1-1) installed on ABB AC800M Product line (System 800xA) CI868 for IEC 61850 communication
- ABB Firmware <=6.1.1202.0 (AC800M version 6.1.1-2) installed on ABB AC800M Product line (System 800xA) CI868 for IEC 61850 communication
- ABB Firmware <=6.2.0006.0 (AC800M version 6.2.0-0) installed on ABB AC800M Product line (System 800xA) CI868 for IEC 61850 communication
- ABB Firmware A_0 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication
- ABB Firmware A_1 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication
- ABB Firmware A_2.003 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication
- ABB Firmware A_3.005 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication
- ABB Firmware A_4.001 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication
- ABB Firmware B_0.005 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication
- ABB Firmware >=3.10|<=3.52 installed on ABB Symphony Plus MR (Melody Rack) PM 877 for IEC 61850 communication
- Summary
- A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed above. An attacker with access to IEC 61850 networks could exploit the vulnerability by using a specially crafted 61850 packet, forcing the communication interfaces of the PM 877, CI850 and CI868 modules into fault mode or causing unavailability of the S+ Operations 61850 connectivity, resulting in a denial-of-service situation. The System 800xA IEC61850 Connect is not affected. Note: This vulnerability does not impact on the overall availability and functionality of the S+ Operations node, only the 61850 communication function.
- Remediation
- ABB advises all customers to review their installations to determine if they are using an impacted product as listed above, no further analysis or tools are needed to make this determination. The recommended immediate actions per product are listed below: - CI868 (for AC 800M) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in 6.1.1 and 7.0 tracks for 800xA. AC 800M 6.1.1-3 is planned for Q2 2027, AC 800M 7.0 has been released in December 2025. - CI850 (for Symphony Plus SD Series) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version C_0 or later (planned Q2 2026). - PM 877 (Symphony Plus MR) Devices with firmware versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected with firmware version 3.53 or later (planned Q1 2026). - S+ Operations Versions reported in Affected products are vulnerable. All the vulnerabilities will be corrected in version 3.4 or later (released in January 2026). ABB recommends customers apply updates, as they become available, at their earliest convenience. It is also advisable to review the Mitigating Factors, Workarounds and General security recommendations sections for additional actions which may help reduce overall risk.
