{ "document": { "acknowledgments": [ { "organization": "ABB PSIRT", "summary": "reported these vulnerabilities to CISA." } ], "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Disclosure is not limited", "tlp": { "label": "WHITE", "url": "https://www.cisa.gov/news-events/news/traffic-light-protocol-tlp-definitions-and-usage" } }, "lang": "en", "notes": [ { "category": "summary", "text": "ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits these vulnerabilities could potentially access sensitive information, cause denial of service, or disrupt system availability.", "title": "Summary" }, { "category": "other", "text": "For additional instructions and support please contact your local ABB service organization. For contact information, see www.abb.com/contactcenters.\n\nInformation about ABB\u2019s cyber security program and capabilities can be found at www.abb.com/cybersecurity.", "title": "Support" }, { "category": "legal_disclaimer", "text": "The information in this document is subject to change without notice, and should not be construed as a commitment by ABB.\n\nABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages.\n\nThis document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\n\nAll rights to registrations and trademarks reside with their respective owners.\n", "title": "Notice" }, { "category": "other", "text": "The following should be taken into consideration when planning system protection.\n- Recognizing and familiarizing all parts of the system and the system's communication links.\n- Removing all unnecessary communication links in the system.\n- Rating the security level of remaining connections and improving them with applicable methods to reach the required security level.\n- Hardening the system by removing or deactivating all unused processes, communication ports, and services.\n- Checking that the whole system has valid backups available from all applicable parts.\n- Collecting and storing backups of the system components and keeping those up to date.\n- Removing all unnecessary user accounts.\n- Define the role-based access right and follow the principle of least privilege.\n- Defining password policies.\n- Changing default passwords and using strong passwords.\n- Checking that the link from a substation to an upper-level system uses strong encryption and authentication.\n- Segregating public networks (untrusted) from automation networks (trusted).\n- Segmenting traffic and networks.\n- Using firewalls and demilitarized zones.\n- Assessing and patching the system periodically.\n- Using malware protection in workstations and keeping those up to date.\n", "title": "General security recommendations" }, { "category": "other", "text": "ABB has a rigorous internal cyber security continuous improvement process which involves regular testing with industry leading tools and periodic assessments to identify potential product issues. Occasionally an issue is determined to be a design or coding flaw with implications that may impact product cyber security.\n\nWhen a potential product vulnerability is identified or reported, ABB immediately initiates our vulnerability handling process. This entails validating if the issue is in fact a product issue, identifying root causes, determining what related products may be impacted, developing a remediation, and notifying end users and governmental organizations.\n\nThe resulting Cyber Security Advisory intends to notify customers of the vulnerability and provide details on which products are impacted, how to mitigate the vulnerability or explain workarounds that minimize the potential risk as much as possible. The release of a Cyber Security Advisory should not be misconstrued as an affirmation or indication of an active threat or ongoing campaign targeting the products mentioned here. If ABB is aware of any specific threats, it will be clearly mentioned in the communication.\n\nThe publication of this Cyber Security Advisory is an example of ABB\u2019s commitment to the user community in support of this critical topic. Responsible disclosure is an important element in the chain of trust we work to maintain with our many customers. The release of an Advisory provides timely information which is essential to help ensure our customers are fully informed.", "title": "Purpose" }, { "category": "faq", "text": "What causes this vulnerability?\n- The vulnerability is caused by the use of an outdated MongoDB 4.2 component, which contains known security weaknesses.\n\nWhat are IIoT Services?\n- IIoT Services are a set of distributed software components designed to enable industrial data collection, processing, and integration across multiple systems. They can be deployed on separate machines or in the cloud, and use web-based technologies to ensure easy access, interoperability, and support across different devices.\n\nWhat might an attacker use the vulnerability to do?\n- An attacker exploiting these vulnerabilities could read sensitive memory contents or crash the MongoDB service, causing denial of service. Since v4.2 is end of life and multiple CVEs have been disclosed publicly, exposed instances risk unauthenticated data exfiltration, not just downtime.\n\nHow could an attacker exploit this vulnerability?\n- An attacker could attempt to interact with the MongoDB service through network access or malicious input to exploit known vulnerabilities.\n\nCould this vulnerability be exploited remotely? \n- Yes, an attacker with network access to the affected system could attempt exploitation.\n\nCan functional safety be affected by an exploit of this vulnerability?\n- No direct impact on functional safety is expected. However, system availability may be affected.\n\nWhen this security advisory was issued, had this vulnerability been publicly disclosed?\n- Yes, the MongoDB 4.2 CVEs are publicly disclosed. However, zenon's specific exposure, bundling this vulnerable version has not itself been publicly disclosed; it was identified during this assessment.\n\nWhen this security advisory was issued, had ABB received any reports that this vulnerability was being exploited?\n- No, ABB had not received any information indicating that this vulnerability had been exploited when this security advisory was originally issued.\n", "title": "Frequently Asked Questions" }, { "category": "legal_disclaimer", "text": "This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).", "title": "Legal Notice and Terms of Use" }, { "category": "other", "text": "This ICSA is a verbatim republication of ABB PSIRT 9AKK108472A9037 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided \"as-is\" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact ABB PSIRT directly for any questions regarding this advisory.", "title": "Advisory Conversion Disclaimer" }, { "category": "general", "text": "CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.", "title": "Recommended Practices" }, { "category": "general", "text": "Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet.", "title": "Recommended Practices" }, { "category": "general", "text": "Locate control system networks and remote devices behind firewalls and isolate them from business networks.", "title": "Recommended Practices" }, { "category": "general", "text": "When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices.", "title": "Recommended Practices" }, { "category": "general", "text": "CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.", "title": "Recommended Practices" }, { "category": "general", "text": "CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.", "title": "Recommended Practices" }, { "category": "general", "text": "CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.", "title": "Recommended Practices" }, { "category": "general", "text": "Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.", "title": "Recommended Practices" }, { "category": "other", "text": "Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater", "title": "Critical infrastructure sectors" }, { "category": "other", "text": "Worldwide", "title": "Countries/areas deployed" }, { "category": "other", "text": "Switzerland", "title": "Company headquarters location" } ], "publisher": { "category": "other", "contact_details": "central@cisa.dhs.gov", "name": "CISA", "namespace": "https://www.cisa.gov/" }, "references": [ { "category": "self", "summary": "ABB CYBERSECURITY ADVISORY - CSAF Version ", "url": "https://psirt.abb.com/csaf/2026/9akk108472a9037.json" }, { "category": "self", "summary": "ABB CYBERSECURITY ADVISORY - PDF Version ", "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch" }, { "category": "self", "summary": "ICS Advisory ICSA-26-218-01 JSON", "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-218-01.json" }, { "category": "self", "summary": "ICS Advisory ICSA-26-218-01 - Web Version", "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/resources-tools/resources/ics-recommended-practices" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/topics/industrial-control-systems" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf" }, { "category": "external", "summary": "Recommended Practices", "url": "https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b" } ], "title": "ABB Ability Zenon", "tracking": { "current_release_date": "2026-08-06T06:00:00.000000Z", "generator": { "date": "2026-08-04T16:18:44.130262Z", "engine": { "name": "CISA CSAF Generator", "version": "1.5.0" } }, "id": "ICSA-26-218-01", "initial_release_date": "2026-07-30T00:30:00.000000Z", "revision_history": [ { "date": "2026-07-30T00:30:00.000000Z", "legacy_version": "Initial", "number": "1", "summary": "Initial version" }, { "date": "2026-08-06T06:00:00.000000Z", "legacy_version": "CISA Republication", "number": "2", "summary": "Initial CISA Republication of ABB PSIRT 9AKK108472A9037 advisory" } ], "status": "final", "version": "2" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version_range", "name": "/all", "product": { "name": "ABB Ability Zenon /all", "product_id": "CSAFPID-0001" } } ], "category": "product_name", "name": "Ability Zenon" } ], "category": "vendor", "name": "ABB" }, { "branches": [ { "category": "product_version", "name": "4.2", "product": { "name": "IIoT services with MongoDB 4.2", "product_id": "CSAFPID-0002" } } ], "category": "product_name", "name": "IIoT services with MongoDB" } ], "relationships": [ { "category": "installed_on", "full_product_name": { "name": "IIoT services with MongoDB 4.2 installed on ABB Ability Zenon /all", "product_id": "CSAFPID-0003" }, "product_reference": "CSAFPID-0002", "relates_to_product_reference": "CSAFPID-0001" } ] }, "vulnerabilities": [ { "cve": "CVE-2025-14847", "cwe": { "id": "CWE-130", "name": "Improper Handling of Length Parameter Inconsistency" }, "notes": [ { "category": "description", "text": "Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2025-14847 ", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14847" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2025-14847" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/130.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "environmentalScore": 7.3, "environmentalSeverity": "HIGH", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "NONE", "privilegesRequired": "NONE", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 7.3, "temporalSeverity": "HIGH", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2025-14847" }, { "cve": "CVE-2020-7928", "cwe": { "id": "CWE-158", "name": "Improper Neutralization of Null Byte or NUL Character" }, "notes": [ { "category": "description", "text": "A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2020-7928", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7928" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7928" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/158.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "environmentalScore": 6.4, "environmentalSeverity": "MEDIUM", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "NONE", "privilegesRequired": "LOW", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 6.4, "temporalSeverity": "MEDIUM", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2020-7928" }, { "cve": "CVE-2020-7921", "cwe": { "id": "CWE-182", "name": "Collapse of Data into Unsafe Value" }, "notes": [ { "category": "description", "text": "Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3and MongoDB Server v3.6 versions prior to 3.6.18.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2020-7921", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7921" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7921" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/182.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "environmentalScore": 5.2, "environmentalSeverity": "MEDIUM", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 5.2, "temporalSeverity": "MEDIUM", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2020-7921" }, { "cve": "CVE-2020-7925", "cwe": { "id": "CWE-475", "name": "Undefined Behavior for Input to API" }, "notes": [ { "category": "description", "text": "Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2020-7925", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7925" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7925" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/475.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "environmentalScore": 7.3, "environmentalSeverity": "HIGH", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "NONE", "privilegesRequired": "NONE", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 7.3, "temporalSeverity": "HIGH", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2020-7925" }, { "cve": "CVE-2020-7929", "cwe": { "id": "CWE-185", "name": "Incorrect Regular Expression" }, "notes": [ { "category": "description", "text": "A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2020-7929", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7929" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7929" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/185.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "environmentalScore": 6.4, "environmentalSeverity": "MEDIUM", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "NONE", "privilegesRequired": "LOW", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 6.4, "temporalSeverity": "MEDIUM", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2020-7929" }, { "cve": "CVE-2020-7923", "cwe": { "id": "CWE-248", "name": "Uncaught Exception" }, "notes": [ { "category": "description", "text": "A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2020-7923", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7923" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7923" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/248.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "environmentalScore": 6.4, "environmentalSeverity": "MEDIUM", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "NONE", "privilegesRequired": "LOW", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 6.4, "temporalSeverity": "MEDIUM", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2020-7923" }, { "cve": "CVE-2021-20330", "cwe": { "id": "CWE-617", "name": "Reachable Assertion" }, "notes": [ { "category": "description", "text": "An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2021-20330", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20330" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20330" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/617.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "environmentalScore": 6.4, "environmentalSeverity": "MEDIUM", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "NONE", "privilegesRequired": "LOW", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 6.4, "temporalSeverity": "MEDIUM", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2021-20330" }, { "cve": "CVE-2021-32036", "cwe": { "id": "CWE-770", "name": "Allocation of Resources Without Limits or Throttling" }, "notes": [ { "category": "description", "text": "An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2021-32036", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32036" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2021-32036" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/770.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.1, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "environmentalScore": 6.9, "environmentalSeverity": "MEDIUM", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "LOW", "privilegesRequired": "LOW", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 6.9, "temporalSeverity": "MEDIUM", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2021-32036" }, { "cve": "CVE-2021-32040", "cwe": { "id": "CWE-787", "name": "Out-of-bounds Write" }, "notes": [ { "category": "description", "text": "It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB Server v4.4 versions prior to and including 4.4.28, MongoDB Server v5.0 versions prior to 5.0.4 and MongoDB Server v4.2 versions prior to 4.2.16. Workaround: >= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2021-32040", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32040" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2021-32040" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/787.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "environmentalScore": 7.3, "environmentalSeverity": "HIGH", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "NONE", "privilegesRequired": "NONE", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 7.3, "temporalSeverity": "HIGH", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2021-32040" }, { "cve": "CVE-2021-20333", "cwe": { "id": "CWE-117", "name": "Improper Output Neutralization for Logs" }, "notes": [ { "category": "description", "text": "Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2021-20333", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20333" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20333" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/117.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "environmentalScore": 5.2, "environmentalSeverity": "MEDIUM", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "LOW", "privilegesRequired": "NONE", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 5.2, "temporalSeverity": "MEDIUM", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2021-20333" }, { "cve": "CVE-2020-7924", "cwe": { "id": "CWE-295", "name": "Improper Certificate Validation" }, "notes": [ { "category": "description", "text": "Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates.This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions prior to 3.6.21; 4.0 versions prior to 4.0.21; 4.2 versions prior to 4.2.11; 100 versions prior to 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2020-7924", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7924" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2020-7924" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/295.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "environmentalScore": 6.4, "environmentalSeverity": "MEDIUM", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "LOW", "privilegesRequired": "NONE", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 6.4, "temporalSeverity": "MEDIUM", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2020-7924" }, { "cve": "CVE-2021-20328", "cwe": { "id": "CWE-295", "name": "Improper Certificate Validation" }, "notes": [ { "category": "description", "text": "Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server\u2019s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CSFLE. The Java async, Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and Azure network fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don\u2019t use Field Level Encryption.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2021-20328", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20328" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20328" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/295.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "HIGH", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "NONE", "baseScore": 6.8, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "environmentalScore": 6.6, "environmentalSeverity": "MEDIUM", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 6.6, "temporalSeverity": "MEDIUM", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2021-20328" }, { "cve": "CVE-2021-20334", "cwe": { "id": "CWE-250", "name": "Execution with Unnecessary Privileges" }, "notes": [ { "category": "description", "text": "A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and later versions; 1.x versions prior to 1.25.0 on Windows.", "title": "CVE description" } ], "product_status": { "known_affected": [ "CSAFPID-0003" ] }, "references": [ { "category": "external", "summary": "NVD - CVE-2021-20334", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20334" }, { "category": "external", "summary": "www.cve.org", "url": "https://www.cve.org/CVERecord?id=CVE-2021-20334" }, { "category": "external", "summary": "cwe.mitre.org", "url": "https://cwe.mitre.org/data/definitions/250.html" }, { "category": "external", "summary": "www.first.org", "url": "https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C" } ], "remediations": [ { "category": "mitigation", "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n- Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n- The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it\u2019s not required: \n- If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section \u201cGeneral security recommendations\u201d for further advise on how to keep your system secure.", "product_ids": [ "CSAFPID-0003" ] } ], "scores": [ { "cvss_v3": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "HIGH", "baseScore": 7.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "environmentalScore": 7.6, "environmentalSeverity": "HIGH", "exploitCodeMaturity": "FUNCTIONAL", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "remediationLevel": "UNAVAILABLE", "reportConfidence": "CONFIRMED", "scope": "UNCHANGED", "temporalScore": 7.6, "temporalSeverity": "HIGH", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C", "version": "3.1" }, "products": [ "CSAFPID-0003" ] } ], "title": "CVE-2021-20334" } ] }