PatchSiren

PatchSiren cyber security CVE debrief

CVE-2015-6607 ABB CVE debrief

CVE-2015-6607 is a privilege escalation vulnerability in SQLite versions before 3.8.9. This vulnerability was used in Android versions before 5.1.1 LMY48T and could allow attackers to gain privileges via a crafted application. The vulnerability has a CVSS score of 3.7 and is considered low severity. The CVE was published on February 18, 2026, and last modified on May 21, 2026. ABB B&R Automation Studio is also affected by this vulnerability, with a fix available in version 6.5.

Vendor
ABB
Product
B&R Automation Studio
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-18
Original CVE updated
2026-05-21
Advisory published
2026-02-18
Advisory updated
2026-05-21

Who should care

Organizations using Android versions before 5.1.1 LMY48T and ABB B&R Automation Studio versions before 6.5 should prioritize patching this vulnerability. Attackers could exploit this vulnerability to gain privileges on affected systems.

Technical summary

The vulnerability exists in SQLite, a widely used database library, before version 3.8.9. SQLite is used in Android before version 5.1.1 LMY48T. An attacker could exploit this vulnerability by creating a crafted application that, when executed, could lead to privilege escalation. The vulnerability's CVSS vector is CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C, indicating a low severity score of 3.7. ABB B&R Automation Studio is also affected, with a fix available in version 6.5.

Defensive priority

Apply patches for SQLite version 3.8.9 or later and upgrade Android to version 5.1.1 LMY48T or later. For ABB B&R Automation Studio, upgrade to version 6.5 or later.

Recommended defensive actions

  • Apply the patch for SQLite version 3.8.9 or later.
  • Upgrade Android to version 5.1.1 LMY48T or later.
  • Upgrade ABB B&R Automation Studio to version 6.5 or later.
  • Implement general security best practices to prevent exploitation.
  • Monitor systems for suspicious activity.

Evidence notes

The CVE description and source metadata indicate that SQLite before 3.8.9, as used in Android before 5.1.1 LMY48T, allows attackers to gain privileges via a crafted application. ABB B&R Automation Studio is also affected, with a fix available in version 6.5. The CVSS score is 3.7, indicating low severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2015-6607 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2015-6607

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2015-6607 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2015-6607

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-141-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://psirt.abb.com/csaf/2026/sa25p007.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.br-automation.com/fileadmin/SA25P007-097a386d.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.