30% (2) 83 views 5 pages

MConfig Insecure Memory Handling Advisory

AI-enhanced description

This advisory details a vulnerability (CVE-2025-9970) in ABB's MConfig software where application credentials are stored in cleartext in memory, potentially allowing an attacker with local network access to extract sensitive information from memory dump files. ABB recommends updating to MConfig version 1.4.9.22 to resolve the issue and implementing defensive measures as outlined in the product manual.

Uploaded by FRANCESCA_622
Download
/ 5
Loading document…