Zurück zur Übersicht

iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator

VDE-2026-051
Last update
17.06.2026 14:00
Published at
17.06.2026 14:00
Vendor(s)
iba AG
External ID
VDE-2026-051
CSAF Document

Summary

A vulnerability has been identified in ibaPDA and ibaDatCoordinator. The affected applications do not properly restrict the .NET BinaryFormatter when deserializing client-server input. This could allow an attacker to cause a type confusion and execute arbitrary code within the affected applications. This is the same issue that exists for the .NET BinaryFormatter: docs.microsoft.com/en-us/visualstudio....

Impact

Remote Code Execution (RCE) running under the service user account, thereby allowing privilege escalation.

Affected Product(s)

Model no. Product name Affected versions
ibaDatCoordinator vers:semver/>=1.0.0|<4.0.7
ibaPDA vers:semver/>=1.0.0|<8.14.0

Vulnerabilities

Expand / Collapse all

Published
17.06.2026 16:50
Weakness
Deserialization of Untrusted Data (CWE-502)
Summary

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoordinator to gain full access to the affected systems.

References

Mitigation

Restrict connections to localhost
- (Info: Applies only to ibaPDA. For ibaDatCoordinator, continue with the next step.) Go to I/O Manager → General and deactivate the option "Automatically open necessary ports in Windows Firewall." (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.)
- Then go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA / ibaDatCoordinator Client and Server.
- Create manual firewall rules for the connection you use for ibaPDA or ibaDatCoordinator and verify that you have the correct ports configured. Help regarding which ports the ibaPDA or ibaDatCoordinator Service uses can be found in the iba Help Center.

Important: After the change, verify that all ibaPDA or ibaDatCoordinator services are working as expected and that the data acquisition is functioning correctly.

Remediation

Update to the fixed versions listed below:
- ibaPDA v8.14.0
- ibaDatCoordinator v4.0.7

Acknowledgments

iba AG thanks the following parties for their efforts:

Revision History

Version Date Summary
1.0.0 17.06.2026 14:00 Initial revision