ABB Ability Zenon
ABB Ability Zenon version 4.2 bundles MongoDB 4.2, which has reached end-of-life and contains multiple known security vulnerabilities (CWE-130, CWE-158, CWE-182, CWE-475, CWE-185, CWE-248, CWE-617, CWE-770, CWE-787, CWE-117, CWE-295, CWE-250). These vulnerabilities are actively being exploited. An attacker with local access or network access to the MongoDB instance could leverage these flaws to access sensitive information, cause denial of service, or disrupt system availability of IIoT Services that manage industrial process data and remote connectivity.
- Local access to the system running ABB zenon with IIoT Services enabled
- Network access to the MongoDB instance (typically localhost unless configured otherwise)
- Knowledge of MongoDB 4.2 vulnerabilities and exploitation techniques
Patching may require device reboot — plan for process interruption
/api/v1/advisories/ca605bf3-87a6-487a-84bb-433d5cec663eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.