ABB AC500 V2
CISA republished an ABB advisory on a buffer over-read in AC500 V2 Modbus handling that can expose fragments of prior responses.
Intelligence analysis by GPT-5.4 Mini
CISA says ABB AC500 V2 PLCs have a Modbus issue that can leak pieces of earlier telegrams in responses to unsupported function codes. The affected range is AC500 V2 firmware 2.5.2 and earlier, with fixes in 2.5.3 and later.
A factory machine controller had a talking problem. When it got asked the wrong kind of question, it could accidentally repeat little scraps of old messages it had already sent.
That is a bit like a printer that, instead of printing a fresh page, leaves old words stuck to the bottom of the new one. The leak is not huge, but it can still reveal private machine chatter.
The fix is to update the controller software and keep these machines away from the open internet. CISA also says to use only the right message types and to keep sensitive data out of this traffic.
Analysis
What happened
CISA published an ICS advisory for ABB AC500 V2 after ABB became aware of a vulnerability in its Modbus server handling. According to the advisory, sending unsupported function codes can trigger invalid responses, and fragments of earlier Modbus telegrams may be appended to the reply.
What is affected
The advisory lists ABB AC500 V2 firmware versions <= 2.5.2 as affected. ABB says the issue is fixed in firmware 2.5.3 and later. CISA gives the flaw CVE-2025-7745 and rates it 5.8 under CVSS 3.1, with the vector indicating network access, no privileges, and no user interaction, but a limited confidentiality impact.
Why operators should care
The most direct risk described here is disclosure: an attacker may recover fragments of prior Modbus responses that were sent earlier by the PLC. CISA also warns that using unsupported Modbus function codes may negatively affect the requesting client. The advisory calls out deployments in critical manufacturing, energy, and water and wastewater, and says these systems are deployed worldwide.
Mitigation and guidance
CISA recommends keeping control systems off the public internet, placing them behind firewalls, and isolating them from business networks. If remote access is required, it recommends stronger access methods such as VPNs, while noting that VPNs still need patching and are only as secure as the devices attached to them. The advisory also recommends not using the Modbus server to send sensitive data and only using supported function codes.
CISA notes this notice is a verbatim republication of ABB PSIRT material converted from CSAF, so the advisory is meant to increase visibility rather than serve as original analysis.
Key points
- CISA republished an ABB advisory for an AC500 V2 Modbus buffer over-read.
- Unsupported Modbus function codes can cause invalid responses that include fragments of prior replies.
- ABB AC500 V2 firmware 2.5.2 and earlier are affected; 2.5.3 and later are fixed.
- CISA recommends isolating control systems from the internet and business networks.
- The advisory applies to critical manufacturing, energy, and water and wastewater deployments.



