ABB Ability Zenon Vulnerabilities Expose Industrial Control Systems to Attacks
CISA has issued an advisory warning of vulnerabilities in ABB Ability Zenon, a widely used industrial control system. The flaws, which affect IIoT services with MongoDB (4.2) installed on ABB Ability Zenon, could allow attackers to bypass security, crash systems, execute …
Intelligence analysis by Llama
CISA has identified two vulnerabilities in ABB Ability Zenon, a widely used industrial control system. The flaws, which affect IIoT services with MongoDB (4.2) installed on ABB Ability Zenon, could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. ABB recommends replacing the bundled MongoDB instance with a supported and patched versi…
Imagine you're in charge of a big factory with lots of machines. These machines are controlled by a computer system called ABB Ability Zenon. Unfortunately, there are some bugs in this system that could let hackers get in and mess with the machines. This could cause problems like the machines crashing or people getting hurt. To fix this, the company that makes the system, ABB, is telling people to update the system or get rid of it if they don't need it.
Analysis
Background
The CISA advisory highlights two vulnerabilities in ABB Ability Zenon, a widely used industrial control system. The flaws, which affect IIoT services with MongoDB (4.2) installed on ABB Ability Zenon, could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data.
Affected Products
The vulnerabilities affect ABB Ability Zenon, a widely used industrial control system. The affected products are IIoT services with MongoDB (4.2) installed on ABB Ability Zenon, with versions prior to 7.0.28, 8.0.17, 8.2.3, 6.0.27, 5.0.32, 4.4.30, and 4.2.0.
Remediations
ABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk:
- Replace bundled MongoDB with a supported version if IIoT services are required.
- Uninstall IIoT Services wherever it's not required.
Metrics
The vulnerabilities have a CVSS base score of 7.5 and a base severity vector string of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The vulnerabilities also have a CVSS version 4.0 base score of 8.7 and a base severity vector string of AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SA:N.
Key points
- CISA has issued an advisory warning of vulnerabilities in ABB Ability Zenon.
- The flaws affect IIoT services with MongoDB (4.2) installed on ABB Ability Zenon.
- The vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data.
- ABB recommends replacing the bundled MongoDB instance with a supported and patched version through manual configuration or uninstalling IIoT Services wherever it's not required.
If the vulnerabilities in ABB Ability Zenon are addressed promptly, the risk of attacks on industrial control systems can be significantly reduced. This could lead to improved security and reduced downtime for critical infrastructure.
If the vulnerabilities in ABB Ability Zenon are not addressed, attackers could exploit them to bypass security, crash systems, execute unauthorized actions, or compromise data. This could lead to significant disruptions to critical infrastructure and potentially even physical harm.



