ABB Zenon Industrial Control Software Exposed to Authentication Bypass

CISA warns of vulnerability allowing unauthorised system reboots in widely deployed industrial automation platform.

Illustration: ABB Zenon Industrial Control Software Exposed to Authentication Bypass

CISA warns of vulnerability allowing unauthorised system reboots in widely deployed industrial automation platform.

  • CVE-2025-8754 affects ABB Ability Zenon versions 7.50 to 14, enabling unauthorised system reboots
  • Vulnerability requires network access but bypasses authentication for critical reboot function
  • No evidence of active exploitation; ABB recommends network access restrictions as primary mitigation

A critical authentication bypass vulnerability in ABB’s widely deployed industrial control software could allow attackers to remotely reboot systems without proper authorisation, CISA warned today.

The vulnerability, tracked as CVE-2025-8754 with a CVSS score of 7.5, affects ABB Ability Zenon Remote Transport Service versions 7.50 through 14. The flaw enables unauthorised access to the Reboot OS function, allowing attackers to trigger system reboots without required authentication.

ABB’s zenon platform is deployed globally across critical infrastructure sectors including chemical, energy, healthcare, water treatment, and manufacturing facilities. The software’s zensyssrv.exe service starts automatically by default, though the Remote Transport Service requires password configuration for normal use.

The vulnerability specifically targets the authentication mechanism for the remote reboot function. While the flaw allows unauthorised system restarts, CISA notes that remote exploitation requires the attacker to have already gained access to the network where the affected ABB system is deployed.

ABB, headquartered in Switzerland, has acknowledged the vulnerability and confirmed no evidence of active exploitation in the wild. The company has not yet released software patches for the affected versions.

As the primary mitigation, ABB recommends restricting network access to systems running the zenon Software Platform. The advisory emphasises implementing access controls to limit exposure of affected systems.

Why It Matters

Industrial control systems like ABB’s zenon platform manage critical infrastructure operations where unexpected reboots could disrupt production, compromise safety systems, or trigger cascading failures across interconnected facilities. The vulnerability’s widespread deployment across chemical, energy, and manufacturing sectors amplifies potential business continuity and safety risks.

For CISOs overseeing operational technology environments, this incident highlights the ongoing challenge of securing industrial control systems that often lack robust authentication mechanisms and may operate with elevated privileges by default.

What To Do Now

  • Audit network access controls for ABB zenon systems and implement additional restrictions as recommended by CISA’s advisory
  • Review authentication requirements for critical functions in industrial control systems across your organisation
  • Monitor ABB’s security bulletins for forthcoming patches addressing CVE-2025-8754

Sources