ABB Ability Zenon

Summary

Multiple vulnerabilities have been identified in ABB Ability Zenon, specifically affecting IIoT services with MongoDB installed. Successful exploitation could lead to security bypass, system crashes, unauthorized actions, or data compromise.

IFF Assessment

FOE

The identified vulnerabilities allow attackers to bypass security controls, crash systems, execute unauthorized actions, or compromise data, posing a direct threat to defenders.

Severity

7.5 High

The CVSS score of 7.8 indicates a High severity vulnerability. This is based on factors such as the potential for unauthorized access, impact on confidentiality and integrity, and the attack vector which could be exploited by an unauthenticated client.

CISA KEV: Listed as actively exploited. Federal patch due: January 19, 2026. Known ransomware use: Unknown.

Defender Context

This advisory highlights critical vulnerabilities in ABB Ability Zenon, impacting several key infrastructure sectors. Defenders must prioritize patching and implementing mitigating controls for affected versions of ABB Ability Zenon and its MongoDB dependencies to prevent potential exploitation.

Read Full Story →