Multiple Security Flaws Found in ABB Ability Zenon Industrial Software
ABB Ability Zenon, an industrial automation platform used across sectors including chemical, communications, and critical manufacturing, has been found to contain multiple vulnerabilities in its IIoT services when MongoDB 4.2 is installed. These affect all versions of the software using this configuration.
The vulnerabilities cover a wide range of technical weaknesses, including improper handling of data length, unsafe character processing, weak certificate validation, and resource allocation issues that could be exploited to overwhelm systems. With a CVSS score of 7.8, these flaws are considered high severity and could allow an attacker to crash affected systems, execute unauthorized actions, or gain access to sensitive data.
While this advisory concerns industrial control system software rather than typical business IT, Australian organisations using ABB Ability Zenon in manufacturing, utilities, or other operational environments should treat this as a priority patching item. Attacks on industrial systems can disrupt operations, damage equipment, or lead to safety incidents, making timely remediation essential.