ABB MConfig Can Leak Plaintext Credentials

A local-access flaw in ABB LVS MConfig can turn the app’s own memory into a credential leak. If passwords are sitting in memory in plaintext, an attacker who can export a runtime dump can recover them later and reuse them against linked systems. ABB’s advisory covers LVS MConfig versions up to 1.4.9.21. The fix is MConfig 1.4.9.22, and ABB says the issue was internally discovered and reported through its PSIRT to CISA. For operators in manufacturing, energy, transportation, and other critical-infrastructure sites, the main question is patch status, not exploit chatter. The risk is exposed credentials that remain useful after the original host issue is corrected.

Part of the PlainSec briefing for 2026-05-26

Sources