ABB T-MAC Plus
View CSAF Summary ABB became aware of vulnerability in the products versions listed as affected in the advisory. An update is available that resolves the reported vulnerabilities. An attacker who successfully exploited any of these vulnerabilities could potentially compromise the system in different ways. The following versions of ABB T-MAC Plus are affected: T-MAC Plus 4.0-24 (CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, CVE-2025-14774) CVSS Vendor Equipment Vulnerabilities v3 9.9 ABB ABB T-MAC Plus Files or Directories Accessible to External Parties, Authorization Bypass Through User-Controlled Key, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Incorrect Authorization Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-14771 File Disclosure in ABB T-MAC Plus web application allows authenticated users to exfiltrate files containing sensitive information via crafted HTTP GET request. View CVE Details Affected Products ABB T-MAC Plus Vendor: ABB Product Version: ABB T-MAC Plus 4.0-24 Product Status: known_affected Remediations Vendor fix ABB has investigated these vulnerabilities to provide adequate protection to customers. The problem is corrected in the following product versions: T-MAC Plus version 4.0-25 ABB recommends that customers apply the update at earliest convenience. Mitigation The misconfigurations on the IIS server, which were reported to security auditing, have been corrected. File Browsing Feature was enabled on that IIS server. That feature along with the default IIS site has been removed. Workaround Workarounds are specific measures that a user can take to help block an attack, for example, temporarily disabling the vulnerable feature may remove the exposure with well-known impact on functionality. ABB has tested the following workarounds. Although these workarounds will not co
CSIRTS triage
- What
- Multiple vulnerabilities could allow an attacker to compromise the system.
- Who is affected
- Users of ABB T-MAC Plus version 4.0-24.
- Urgency
- Remediation is critical due to the high severity of the vulnerabilities.
- Action
- Update to a version that resolves the identified vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch T-MAC Plus
Get an email when a new T-MAC Plus advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-147710.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2025-147720.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2025-147730.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
- Low exploitation riskCVE-2025-147740.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-14771 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-14772 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-14773 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-14774 | coverage & exploitation status | NVD · CVE.org |
More from CISA Cybersecurity Advisories
- criticalSchneider Electric IGSS2026-07-30
- criticalRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- unknownMitsubishi Electric CC-Link IE TSN Communication Protocol2026-07-30
- criticalOpen Source Software: Security Principles and Practices2026-07-30