PatchSiren cyber security CVE debrief
CVE-2015-6607 ABB CVE debrief
CVE-2015-6607 is a privilege escalation vulnerability in SQLite versions before 3.8.9. This vulnerability was used in Android versions before 5.1.1 LMY48T and could allow attackers to gain privileges via a crafted application. The vulnerability has a CVSS score of 3.7 and is considered low severity. The CVE was published on February 18, 2026, and last modified on May 21, 2026. ABB B&R Automation Studio is also affected by this vulnerability, with a fix available in version 6.5.
- Vendor
- ABB
- Product
- B&R Automation Studio
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-02-18
- Original CVE updated
- 2026-05-21
- Advisory published
- 2026-02-18
- Advisory updated
- 2026-05-21
Who should care
Organizations using Android versions before 5.1.1 LMY48T and ABB B&R Automation Studio versions before 6.5 should prioritize patching this vulnerability. Attackers could exploit this vulnerability to gain privileges on affected systems.
Technical summary
The vulnerability exists in SQLite, a widely used database library, before version 3.8.9. SQLite is used in Android before version 5.1.1 LMY48T. An attacker could exploit this vulnerability by creating a crafted application that, when executed, could lead to privilege escalation. The vulnerability's CVSS vector is CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C, indicating a low severity score of 3.7. ABB B&R Automation Studio is also affected, with a fix available in version 6.5.
Defensive priority
Apply patches for SQLite version 3.8.9 or later and upgrade Android to version 5.1.1 LMY48T or later. For ABB B&R Automation Studio, upgrade to version 6.5 or later.
Recommended defensive actions
- Apply the patch for SQLite version 3.8.9 or later.
- Upgrade Android to version 5.1.1 LMY48T or later.
- Upgrade ABB B&R Automation Studio to version 6.5 or later.
- Implement general security best practices to prevent exploitation.
- Monitor systems for suspicious activity.
Evidence notes
The CVE description and source metadata indicate that SQLite before 3.8.9, as used in Android before 5.1.1 LMY48T, allows attackers to gain privileges via a crafted application. ABB B&R Automation Studio is also affected, with a fix available in version 6.5. The CVSS score is 3.7, indicating low severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2015-6607 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2015-6607
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2015-6607 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2015-6607
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-141-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://psirt.abb.com/csaf/2026/sa25p007.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.br-automation.com/fileadmin/SA25P007-097a386d.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.