CVE-2025-3756
A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed above. An attacker with access to IEC 61850 networks could exploit the vulnerability by using a specially crafted 61850 packet, forcing the communication interfaces of the PM 877, CI850 and CI868 modules into fault mode or causing unavailability of the S+ Operations 61850 connectivity, resulting in a denial-of-service situation. The System 800xA IEC61850 Connect is not affected. Note: This vulnerability does not impact on the overall availability and functionality of the S+ Operations node, only the 61850 communication function.
EPSS 0.03% · 8.1th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ABB | ABB Firmware <=1.0031.0 (AC800M version 6.1.0-x) installed on ABB AC800M Product line (System 800xA) CI868 for IEC 61850 communication | |
| ABB | ABB Firmware A_4.001 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication | |
| ABB | ABB Firmware <=6.0.0303.0 (AC800M version 6.0.0-x) installed on ABB AC800M Product line (System 800xA) CI868 for IEC 61850 communication | |
| ABB | ABB Firmware <=6.1.1004.0 AC800M version 6.1.1-0 and 6.1.1-1) installed on ABB AC800M Product line (System 800xA) CI868 for IEC 61850 communication | |
| ABB | ABB Firmware B_0.005 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication | |
| ABB | ABB Firmware <=6.1.1202.0 (AC800M version 6.1.1-2) installed on ABB AC800M Product line (System 800xA) CI868 for IEC 61850 communication | |
| ABB | ABB Firmware 2.3 installed on ABB S+ Operations using IEC 61850 connectivity | |
| ABB | ABB Firmware A_0 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication | |
| ABB | ABB Firmware A_3.005 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication | |
| ABB | ABB Firmware >=3.10|<=3.52 installed on ABB Symphony Plus MR (Melody Rack) PM 877 for IEC 61850 communication | |
| ABB | ABB Firmware A_2.003 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication | |
| ABB | ABB Firmware 2.2 and related service packs installed on ABB S+ Operations using IEC 61850 connectivity | |
| ABB | ABB Firmware 3.3 and related service packs installed on ABB S+ Operations using IEC 61850 connectivity | |
| ABB | ABB Firmware <=6.2.0006.0 (AC800M version 6.2.0-0) installed on ABB AC800M Product line (System 800xA) CI868 for IEC 61850 communication | |
| ABB | ABB Firmware 2.1 and related service packs installed on ABB S+ Operations using IEC 61850 connectivity | |
| ABB | ABB Firmware A_1 installed on ABB Symphony Plus SD Series CI850 for IEC 61850 communication |
Exploit Intelligence
Timeline
- Apr 13, 2026 CVE Published
- Apr 13, 2026 PoC Published
- Apr 14, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
References
- https://psirt.abb.com/csaf/2026/7paa020125.json advisory
- https://search.abb.com/library/Download.aspx?DocumentID=7PAA020125&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://search.abb.com/library/Download.aspx?DocumentID=2VAA003700&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://search.abb.com/library/Download.aspx?DocumentID=8VZZ001882T0002&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://search.abb.com/library/Download.aspx?DocumentID=9ARD171385-611&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://search.abb.com/library/Download.aspx?DocumentID=8VZZ001006T0001&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://search.abb.com/library/Download.aspx?DocumentID=2PAA121027&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://search.abb.com/library/Download.aspx?DocumentID=8VZZ000602T0001&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://search.abb.com/library/Download.aspx?DocumentID=7PAA018617&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://search.abb.com/library/Download.aspx?DocumentID=2PAA122516&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://search.abb.com/library/Download.aspx?DocumentID=8VZZ000368D0066&LanguageCode=en&DocumentPartId=&Action=Launch advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-3756 advisory