CVE-2025-8754

7.5

ABB · ABB Ability zenon

A missing authentication vulnerability exists in ABB Ability zenon, which allows unauthenticated attackers to trigger critical functions.

Executive summary

A critical missing authentication vulnerability in ABB Ability zenon exposes the software to unauthorized access and potential service disruption by unauthenticated remote attackers.

Vulnerability

This vulnerability is classified as CWE-306, where the application fails to verify the identity of a user before executing sensitive operations. The CVSS vector confirms that this flaw is exploitable over the network by an unauthenticated attacker with no user interaction required.

Business impact

The ability for an unauthenticated actor to interact with critical functions poses a significant risk to operational integrity and system availability. With a CVSS score of 7.5, this high-severity vulnerability could lead to unauthorized system state changes or denial of service, potentially resulting in operational downtime or the compromise of industrial control environments.

Remediation

Immediate Action: Review the official ABB security advisory (Document ID 2NGA002743) to identify available patches or configuration changes and apply them to all affected instances immediately.

Proactive Monitoring: Monitor system access logs for unusual administrative activity or unauthorized attempts to reach critical internal endpoints.

Compensating Controls: Implement strict network segmentation and utilize firewalls to restrict access to the zenon interface, ensuring only authorized management stations can communicate with the service.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for unauthenticated remote exploitation, organizations running ABB Ability zenon should prioritize identifying affected versions within their environment. Administrative teams must transition from reliance on perimeter security to hardening the application itself by applying the vendor-supplied updates or implementing the specific mitigations detailed in the ABB security bulletin.

More ABB CVEs

Sources