VORANT. Threat Intelligence Sign in Get the full feed

ABB T-MAC Plus flaws risk terminal system compromise

medium vulnerability manufacturingenergy

ABB patched four vulnerabilities in T-MAC Plus terminal management software allowing file disclosure, privilege escalation, stored XSS, and a DoS against card readers.

ABB disclosed four vulnerabilities affecting T-MAC Plus version 4.0-24, a Terminal Management System used to control operations such as product receipt/dispatch, access control, and tank farm movements at chemical, petroleum, pipeline, and hydrogen terminals worldwide. The flaws stem from IIS server misconfiguration enabling file browsing, improper privilege separation between user roles, a DOM-based stored XSS in the web application, and an unencrypted communication protocol with card readers that can be disrupted via a crafted message if an attacker gains physical access to a serial device.

Exploitation generally requires authenticated access (file disclosure, privilege escalation, XSS) or physical network/device access (the card reader DoS), and ABB states it has not received reports of in-the-wild exploitation. The vendor has released version 4.0-25 to remediate all four issues and corrected the underlying IIS misconfigurations and privilege assignments. CISA republished the advisory and recommends standard ICS network segmentation, minimizing internet exposure, and using secure remote access methods such as VPNs as compensating controls until the update is applied.

Given the product's deployment in critical manufacturing and energy-adjacent terminal operations (petroleum, pipeline, chemical, hydrogen), successful exploitation could expose sensitive operational data, allow unauthorized administrative actions, or disrupt physical access-control/card reader services. The vulnerabilities were responsibly disclosed by a researcher via Italy's national cybersecurity agency (ACN), and no public exploit code or active campaign has been reported.

Mentioned in this report

Vulnerabilities CVE-2025-14771CVE-2025-14772CVE-2025-14773CVE-2025-14774

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-195-03

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free