CISA

ABB Ability Zenon

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data.

The following versions of ABB Ability Zenon are affected:

IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* 

Vendor

Equipment

ABB

ABB Ability Zenon

Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data into Unsafe Value, Undefined Behavior for Input to API, Incorrect Regular Expression, Uncaught Exception, Reachable Assertion, Allocation of Resources Without Limits or Throttling, Out-of-bounds Write, Improper Output Neutralization for Logs, Improper Certificate Validation, Execution with Unnecessary Privileges

Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public He...