AC 800PEC, AC 800PEC ARM, AC 800PEC Tool, Control Terminal (xCT) and AC 800PEC Tool Cheetah Impacted by multiple vulnerabilities in Wibu CodeMeter

Plan PatchCVSS 8.63bhs973333Sep 10, 2026
ABB
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Multiple vulnerabilities in the embedded Wibu CodeMeter license manager affect ABB control platform tools and engineering software. The vulnerabilities allow remote attackers to delete arbitrary files with system privileges, modify configuration data in Server.ini, crash the CodeMeter service and disclose sensitive process memory information, or access license information. Exploitation requires the CodeMeter network server functionality to be enabled (which it may be by default or from previous configuration). Affected versions: AC 800PEC before 5.4.5.2, AC 800PEC ARM all versions, AC 800PEC Tool all versions, AC 800PEC Tool Cheetah all versions, and Control Terminal (xCT) all versions.

What this means
What could happen
An attacker with network access to these systems could delete files with system privileges, modify configuration settings, crash the license manager causing service disruption, and access sensitive license or configuration data. This could lead to loss of control system functionality or unauthorized changes to device behavior.
Who's at risk
ABB AC 800PEC control platform operators and engineering workstations running AC 800PEC, AC 800PEC ARM, AC 800PEC Tool, AC 800PEC Tool Cheetah, or Control Terminal (xCT) with CodeMeter license manager enabled. This impacts PLC and control system software licensing across manufacturing, utilities, and process automation environments.
How it could be exploited
An attacker with network access to the CodeMeter license manager (if network server functionality is enabled) can send malformed requests to trigger arbitrary file deletion, configuration file modification, denial of service, or information disclosure. No authentication is required if the network server is active.
Prerequisites
  • Network access to CodeMeter network server port (if enabled)
  • CodeMeter network server functionality must be enabled on the target system
remotely exploitableno authentication requiredlow complexityaffects control system functionalityno patch available for some products in classic lifecycle
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (5)
5 with fix
ProductAffected VersionsFix Status
AC 800PEC <5.4.5.2<5.4.5.25.4.5.2
AC 800PEC ARM /all/allFix available
AC 800PEC Tool /all/allFix available
AC 800PEC Tool Cheetah /all/allFix available
Control Terminal (xCT) /all/allFix available
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDDisable CodeMeter network server functionality by opening Registry Editor, navigating to HKEY_LOCAL_MACHINE\SOFTWARE\WIBUSYSTEMS\CodeMeter\Server\CurrentVersion, changing IsNetworkServer from 1 to 0, and restarting CodeMeter
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate AC 800PEC to version 5.4.5.2 or later
HOTFIXUpdate CodeMeter Runtime to version 8.41a or 9.10 from Wibu download site independent of tool installation
Long-term hardening
0/1
HARDENINGRestrict network access to CodeMeter license manager ports from untrusted networks
API: /api/v1/advisories/73816373-4173-498d-a9ef-38cc0f117e23

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

AC 800PEC, AC 800PEC ARM, AC 800PEC Tool, Control Terminal (xCT) and AC 800PEC Tool Cheetah Impacted by multiple vulnerabilities in Wibu CodeMeter | CVSS 8.6 - OTPulse