CVE-2025-6073
7.5ABB · RMC-100 and RMC-100 LITE
A stack-based buffer overflow exists in the ABB RMC-100 and RMC-100 LITE REST interface, which may allow an attacker to cause a denial of service.
Executive summary
A stack-based buffer overflow vulnerability in the ABB RMC-100 and RMC-100 LITE series poses a significant risk to industrial control network availability.
Vulnerability
The vulnerability is a stack-based buffer overflow (CWE-121) occurring within the REST interface. Successful exploitation requires the interface to be enabled, user authentication to be active, and the prior exploitation of CVE-2025-6074 to bypass initial controls.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity level primarily due to the potential for service disruption. In an industrial environment, the unexpected crash of a control device can lead to unplanned downtime, loss of operational visibility, and potential safety risks if the device is managing critical processes.
Remediation
Immediate Action: Monitor the official ABB security advisory portal for the release of firmware updates and apply them to all affected RMC-100 and RMC-100 LITE units as soon as they become available.
Proactive Monitoring: Review system logs for unauthorized access attempts to the REST interface and monitor for unusual traffic patterns targeting control network communication ports.
Compensating Controls: Restrict network access to the REST interface by implementing strict firewall rules that limit communication to authorized management stations only.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the potential for service disruption in industrial control environments, operators should treat this vulnerability with high priority. We recommend isolating affected devices from public or untrusted network segments until official patches are applied and verified.
More ABB CVEs
Sources
Originally found and disclosed by ABB thanks Claroty Team82 Research for helping to identify the vulnerabilities and protecting our customers, per the CVE Program record.