ABB Drive Composer, Automation Builder, Mint Workbench
ABB Drive Composer, Automation Builder, and Mint Workbench contain an improper privilege assignment vulnerability (CWE-269) that could allow a local user to execute arbitrary code with elevated privileges. The vulnerability affects Drive Composer Entry and Pro versions 2.0 through 2.7, Automation Builder versions 1.1.0 through 2.5.0, and Mint Workbench builds 5866 and earlier. Successful exploitation requires local access to a workstation running the affected software; remote exploitation is not possible.
- Local access to a workstation running the vulnerable ABB software
- User account with login privileges on the affected workstation
- The vulnerable software application must be installed
Patching may require device reboot — plan for process interruption
/api/v1/advisories/8b4dd5bb-6e80-4bc6-b8d3-3ec359e84463Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.