PT-2022-22387 · Abb · Abb Zenon

Published

2022-08-24

·

Updated

2022-08-30

·

CVE-2022-34838

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions ABB Zenon version 8.20
Description The issue allows an attacker to add or alter data points and corresponding attributes. Once such engineering data is used, the data visualization will be altered for the end user.
Recommendations For ABB Zenon version 8.20, consider restricting access to sensitive data points and attributes until a fix is available. As a temporary workaround, review and monitor all changes to engineering data to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-34838

Affected Products

Abb Zenon