ABB Camera Connect Needs Its Own VLC Fix

Patching VLC on its own does not clear ABB Ability Camera Connect. The vulnerable copy lives inside ABB’s installer, so Camera Connect stays exposed until ABB updates the embedded component or the product to 1.5.0.15. ABB says Camera Connect versions 1.5.0.14 and below shipped with VLC 2.2.4, which is affected by CVE-2024-46461. A malicious MMS stream could trigger an integer overflow that can crash VLC or potentially lead to arbitrary code execution with the target user’s privileges. The practical risk is a false sense of closure from normal app-level patch tracking. In fleets that rely on vendor-packaged libraries, the upstream fix and the deployed fix are not the same thing.

Part of the PlainSec briefing for 2026-05-26

Sources