CYBERSECURITYTRACKER
TRACKING6,916 stories in this site build1,447 vulnerability news stories in this site build
Permanent story citation

ABB Ability Zenon

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4006

As cited

Copy frozen at (site build).

vulnerabilities

ABB Ability Zenon

ABB Ability Zenon, an industrial IoT platform with bundled MongoDB, contains multiple vulnerabilities in its MongoDB component that could allow unauthenticated attackers to read uninitialized heap memory or access arbitrary memory through specially crafted queries. The affected versions span MongoDB 3.6 through 8.2, with CVSS scores ranging from 7.5 to 8.7. ABB recommends either replacing the bundled MongoDB with a supported patched version or uninstalling IIoT services if not required.

Why it matters: Organizations running ABB Ability Zenon in critical infrastructure sectors (energy, water, healthcare, chemical, communications) worldwide face data exposure and potential system compromise; practitioners should immediately assess whether IIoT services are required and either upgrade MongoDB or remove the component.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

ABB Ability Zenon

ABB Ability Zenon, an industrial IoT platform with bundled MongoDB, contains multiple vulnerabilities in its MongoDB component that could allow unauthenticated attackers to read uninitialized heap memory or access arbitrary memory through specially crafted queries. The affected versions span MongoDB 3.6 through 8.2, with CVSS scores ranging from 7.5 to 8.7. ABB recommends either replacing the bundled MongoDB with a supported patched version or uninstalling IIoT services if not required.

Why it matters: Organizations running ABB Ability Zenon in critical infrastructure sectors (energy, water, healthcare, chemical, communications) worldwide face data exposure and potential system compromise; practitioners should immediately assess whether IIoT services are required and either upgrade MongoDB or remove the component.

VendorsMongoDB
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary