mapp Services Use of Weak Authenticators in mapp Audit

Plan PatchCVSS 8.7sa26p012Sep 3, 2026
Manufacturing
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionNone needed
Summary

A vulnerability in mapp Services versions prior to 6.8.0 allows an attacker to bypass authentication on the OPC UA server component used by mapp Audit due to weak authenticators with insufficient entropy. An unauthenticated attacker with network access to the OPC UA server can exploit this to gain unauthorized access to the server. The vulnerability only affects systems that actively use and configure mapp Audit functionality.

What this means
What could happen
An attacker could gain unauthorized access to the OPC UA server component in mapp Audit, potentially allowing them to read process data, modify control parameters, or disrupt operations on connected manufacturing systems.
Who's at risk
Manufacturing facilities using ABB mapp Services with mapp Audit functionality should apply this fix. This applies to any production environment running mapp Audit for monitoring or auditing purposes, particularly in discrete manufacturing and process automation systems where OPC UA servers control or monitor equipment.
How it could be exploited
An attacker on the network sends authentication requests to the OPC UA server component used by mapp Audit. Due to weak authenticators with insufficient entropy, the attacker can bypass authentication and gain unauthorized server access without valid credentials.
Prerequisites
  • Network access to the OPC UA server port on devices running mapp Services with mapp Audit functionality enabled
  • mapp Audit feature must be actively configured and in use on the target system
remotely exploitableno authentication requiredaffects OPC UA server accesshigh CVSS score (8.7)
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
mapp Services <6.8.0All versionsmapp Audit
Remediation & Mitigation
0/4
Do now
0/2
WORKAROUNDRestrict network access to the OPC UA server to only trusted engineering stations and authorized runtime components using firewall rules or network segmentation
WORKAROUNDDisable mapp Audit functionality if not actively needed in your projects
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate mapp Services to version 6.8.0 or later
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate mapp Services systems on a dedicated automation network segment separate from untrusted networks
API: /api/v1/advisories/86565c72-75fd-4f6f-9773-edc5bc9a1495

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.