Changeflow GovPing Data Privacy & Cybersecurity ABB 800xA CI868 and Symphony Melody PM877 Denia...
Priority review Guidance Added Final

ABB 800xA CI868 and Symphony Melody PM877 Denial of Service Vulnerability

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published
Detected
Email

Summary

CERT-Bund issued a security advisory regarding a denial of service vulnerability in ABB industrial control systems 800xA and Symphony Melody. The vulnerability (CVSS Base Score 6.5) affects the CI868 module for AC800M and PM877 for Symphony Melody Plus MR when specific version thresholds are met. An attacker from an adjacent network could exploit this vulnerability to cause service disruption. Mitigation measures are available from ABB.

What changed

CERT-Bund disclosed a denial of service vulnerability in ABB 800xA and ABB Symphony Melody industrial control systems affecting specific versions of the CI868 module (versions below 6.1.1 and 7.0) and PM877 controller (versions below 3.53). The vulnerability has a CVSS Base Score of 6.5 (medium severity) and can be exploited by an attacker from an adjacent network to disrupt system operations.

Organizations operating affected ABB industrial control systems in process automation environments should review their asset inventory for these products and implement available mitigation measures. While no patch or update is explicitly mandated, failure to address this vulnerability could result in operational disruption of critical process control systems.

What to do next

  1. Review affected ABB 800xA and Symphony Melody systems for applicable versions
  2. Implement available mitigations from ABB
  3. Monitor for security updates from vendor

Archived snapshot

Apr 15, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

[WID-SEC-2026-1086] ABB 800xA CI868 (für AC 800M) und PM877 (Symphony Plus MR): Schwachstelle ermöglicht Denial of Service CVSS Base Score 6.5 (mittel) CVSS Temporal Score 5.7 (mittel) Remoteangriff ja Datum 13.04.2026 Stand 14.04.2026 Mitigation ja

Betroffene Systeme

Betriebssystem

  • BIOS/Firmware
  • Sonstiges
  • UNIX
  • Windows

Produktbeschreibung

800xA ist ein Prozessleitsystem des Herstellers ABB zur Automatisierung verfahrenstechnischer Prozesse.
Symphony Melody ist ein Prozessleitsystem des Herstellers ABB zur Automatisierung verfahrenstechnischer Prozesse.

Produkte

13.04.2026
- ABB 800xA AC800M CI868 <6.1.1

  • ABB 800xA AC800M CI868 <7.0

  • ABB Symphony Melody Plus MR PM 877 <3.53

Angriff

Angriff

Ein Angreifer aus einem angrenzenden Netzwerk kann eine Schwachstelle in ABB 800xA und ABB Symphony Melody ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Get daily alerts for CERT-Bund Security Advisories

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from CERT-Bund.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
CERT-Bund
Published
April 13th, 2026
Instrument
Guidance
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
WID-SEC-2026-1086

Who this affects

Applies to
Manufacturers Energy companies Industrial firms
Industry sector
5112 Software & Technology
Activity scope
Industrial control system security Process automation vulnerability management Denial of service mitigation
Geographic scope
Germany DE

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Critical Infrastructure Industrial Automation Operational Technology Security

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!