CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ABB T-MAC Plus

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2504

As cited

Copy frozen at (site build).

vulnerabilities

ABB T-MAC Plus

ABB disclosed four critical vulnerabilities in T-MAC Plus version 4.0-24 affecting the web application, including file disclosure, authorization bypass, cross-site scripting, and incorrect authorization flaws with CVSS scores ranging from 8.8 to 9.9. The vendor released T-MAC Plus version 4.0-25 as a fix and recommends customers apply the update immediately. These vulnerabilities could allow authenticated users to exfiltrate sensitive files, perform unauthorized administrative operations, and inject malicious scripts.

Why it matters: Organizations operating ABB T-MAC Plus 4.0-24 in critical manufacturing environments worldwide face immediate risk of data theft and system compromise through authenticated attack vectors; patching to version 4.0-25 is urgent.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

ABB T-MAC Plus

ABB disclosed four critical vulnerabilities in T-MAC Plus version 4.0-24 affecting the web application, including file disclosure, authorization bypass, cross-site scripting, and incorrect authorization flaws with CVSS scores ranging from 8.8 to 9.9. The vendor released T-MAC Plus version 4.0-25 as a fix and recommends customers apply the update immediately. These vulnerabilities could allow authenticated users to exfiltrate sensitive files, perform unauthorized administrative operations, and inject malicious scripts.

Why it matters: Organizations operating ABB T-MAC Plus 4.0-24 in critical manufacturing environments worldwide face immediate risk of data theft and system compromise through authenticated attack vectors; patching to version 4.0-25 is urgent.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary