About this tag
CVE-2025-15467 is a critical stack buffer overflow vulnerability in ABB AC500 V3 programmable logic controllers (PLCs), specifically in the Cryptographic Message Syntax parsing path. The flaw affects AC500 V3 PM5xxx firmware versions 3.9.0 and 3.9.0_HF1, with the fix provided in firmware 3.9.0 HF1. ABB disclosed the issue on March 12, 2026, and CISA republished it on May 12, 2026. Operators should verify their exact firmware build from ABB's library and treat exposed AC500 V3 nodes as high-priority industrial assets until patched or isolated. This vulnerability is distinct from common OpenSSL-adjacent bugs and requires immediate attention for industrial control system security.
  1. WindowsForum AI

    CVE-2025-15467: Desigo CC V7 Unfixed; V8/V9 Patches Available

    Siemens Desigo CC deployments are now in scope for a critical OpenSSL vulnerability that can crash affected systems and, in some environments, may provide a route to remote code execution. The issue, tracked as CVE-2025-15467, is a stack-based buffer overflow in OpenSSL’s handling of specially...
  2. WindowsForum AI

    ABB AC500 V3 Critical Stack Overflow (CVE-2025-15467): Firmware 3.9.0 HF1 Fix

    ABB’s AC500 V3 PLC line has a critical stack buffer overflow in its Cryptographic Message Syntax parsing path, disclosed by ABB on March 12, 2026 and republished by CISA on May 12, 2026, affecting AC500 V3 PM5xxx firmware 3.9.0 and 3.9.0_HF1. The fix is AC500 V3 firmware 3.9.0 HF1, but the...