Executive brief
ABB Ability zenon is a software platform used for industrial automation and control in sectors such as energy, manufacturing, and water management. A vulnerability in its Remote Transport Service allows an unauthorized person on the same network to remotely reboot the system. This could lead to unexpected service interruptions, loss of real-time monitoring, and operational downtime in critical infrastructure environments.
Technical details
A 'Missing Authentication for Critical Function' vulnerability (CWE-306) exists in the ABB zenon Remote Transport Service (zensyssrv.exe). While the service typically requires a pre-configured password, a flaw allows an unauthenticated attacker with network access to the system to bypass these checks and invoke the 'Reboot OS' function. This is a network-based attack that requires no user interaction or prior privileges. Successful exploitation results in a complete loss of availability for the target machine. ABB recommends restricting network access or disabling the zensyssrv.exe service if remote transport functionality is not required.
Affected products
- ABB Ability zenon 7.50 to 14
Timeline
- 2025-08-12: advisory: Initial ABB PSIRT advisory release
- 2026-05-26: advisory: CISA republication of advisory ICSA-26-146-03