


Perceptive Security
SOC/SIEM Consultancy

ABB Ability Symphony Plus Engineering
Published:
30 April 2026 at 12:00:00
Alert date:
30 April 2026 at 17:05:34
Source:
cisa.gov
Critical Infrastructure, Enterprise Applications, Database & Storage
ABB Ability Symphony Plus Engineering versions 2.2 through 2.4 SP2 are affected by multiple critical vulnerabilities in PostgreSQL version 13.11 and earlier. These include integer overflow, SQL injection, TOCTOU race condition, and privilege dropping errors. Attackers with network access can execute arbitrary code and potentially compromise entire systems. ABB recommends upgrading to version 2.4 SP2 RU1 or later. The vulnerabilities affect critical infrastructure sectors including Chemical, Critical Manufacturing, Energy, and Water/Wastewater worldwide.
Technical details
Mitigation steps:
Affected products:
ABB Ability Symphony Plus Engineering
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-120-06
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-120-06.json
https://www.cve.org/CVERecord?id=CVE-2023-5869
https://www.cve.org/CVERecord?id=CVE-2023-39417
https://www.cve.org/CVERecord?id=CVE-2024-7348
https://www.cve.org/CVERecord?id=CVE-2024-0985
https://cwe.mitre.org/data/definitions/190.html
https://cwe.mitre.org/data/definitions/89.html
https://cwe.mitre.org/data/definitions/367.html
https://cwe.mitre.org/data/definitions/271.html
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
