ABB LVS MConfig
CISA says ABB's MConfig stores sensitive data in memory, letting a local attacker with host access extract credentials from a dump file.
Intelligence analysis by GPT-5.4 Mini
CISA issued an ICS advisory for ABB LVS MConfig after ABB found a memory-handling flaw that could expose user credentials. The fix is in MConfig 1.4.9.22, and the issue requires local access to the host machine.
ABB’s software had a weak spot where secret login details could stick around in the computer’s working memory.
If someone gets near the right computer and grabs a memory dump, they might find those secrets, like finding a note left on a desk instead of locked in a drawer.
ABB fixed it in a newer version. CISA is warning people because the software helps control important equipment, so stolen passwords could cause real trouble.
Analysis
What happened
CISA published an advisory for ABB LVS MConfig after ABB reported an internally discovered vulnerability. The problem affects MConfig versions up to and including 1.4.9.21 and is tracked as CVE-2025-9970.
Impact
According to the advisory, an attacker with access to the local network or, more specifically in the FAQ, physical access to the host machine can export a memory dump while the application is running. If authentication data is stored in plain text in memory, the dump may reveal user credentials. CISA lists the CVSS v3.1 score at 7.4, which it classifies as high.
Why this matters
MConfig is used to parameterize ABB LV switchgear components, including motor and feeder controllers, operation panels, temperature monitoring solutions, and protocol converters. ABB says that if an attacker gets credentials and can access the host machine and switch room components, they may be able to modify settings and potentially affect correct operation.
Fix and mitigation
ABB says the issue is resolved in MConfig version 1.4.9.22. The advisory says the update clears authentication-related memory after login and hashes passwords with SHA256. ABB also advises customers to update and, if upgrading is not feasible, follow the product manual's defensive guidance and mitigation factors.
Key points
- CISA says ABB LVS MConfig has a memory-handling flaw that can expose credentials.
- The issue affects MConfig versions up to and including 1.4.9.21.
- ABB says the vulnerability is fixed in version 1.4.9.22.
- The advisory says exploitation requires access to the host machine, not remote network access alone.
- Stolen credentials could let an attacker change settings on connected switchgear components.



