PatchSiren cyber security CVE debrief
CVE-2025-6072 ABB CVE debrief
CVE-2025-6072 is a high-severity ABB RMC-100 / RMC-100 LITE issue in the REST interface path. According to the advisory, if the REST interface is enabled and an attacker already has access to the control network, exploitation of CVE-2025-6074 can let the attacker use JSON configuration input to overflow the expiration-date field. ABB provides fixed releases for affected RMC-100 and RMC-100 LITE versions.
- Vendor
- ABB
- Product
- RMC-100
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-07-03
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-07-03
- Advisory updated
- 2026-05-14
Who should care
ABB RMC-100 and RMC-100 LITE owners, OT/ICS operators, plant engineering teams, and security administrators responsible for control-network segmentation and REST interface exposure should review this issue. Priority is highest for environments that have the REST interface enabled or any control-network path accessible to untrusted users.
Technical summary
The CISA/ABB advisory describes an attack chain, not a standalone issue: CVE-2025-6072 becomes relevant when the device REST interface is enabled and an attacker can access the control network, while CVE-2025-6074 is also exploited. Under those conditions, crafted JSON configuration content can overflow the expiration-date field. The advisory assigns CVSS 3.1 7.5 (HIGH) with availability impact only, and lists fixed versions for both affected product lines.
Defensive priority
High
Recommended defensive actions
- Upgrade affected ABB RMC-100 systems to version 2105457-046 or later.
- Upgrade affected ABB RMC-100 LITE systems to version 2106229-018 or later.
- Disable the REST interface unless it is operationally required.
- Restrict and segment access to the control network so only authorized engineering systems can reach the devices.
- Review exposure of JSON-based management/configuration workflows and limit access to trusted administrators only.
- Use CISA and ABB advisory guidance to confirm affected version ranges before scheduling remediation.
Evidence notes
This debrief is based only on the supplied CISA CSAF source item and the linked official advisory records. The advisory was published on 2025-07-03 and updated on 2026-05-14. It states that the issue affects ABB RMC-100 versions 2105457-043 through 2105457-045 and ABB RMC-100 LITE versions 2106229-015 through 2106229-016, with fixes in RMC-100 2105457-046 and RMC-100 LITE 2106229-018. The description explicitly requires the REST interface to be enabled, attacker access to the control network, and exploitation of CVE-2025-6074.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-6072 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-6072
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-6072 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-6072
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-196-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://psirt.abb.com/csaf/2025/9akk108471a3623.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-196-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.