CVE-2024-8036 is a vulnerability affecting certain ABB product versions in which specially crafted firmware or configuration data sent to a system node can trigger improper handling of exceptional conditions. The issue can be exploited to leave the node stopped or inaccessible, and available reporting indicates the flaw is associated with unsafe handling of critical configuration state during update or file-management operations. In observed scenarios, deletion or malformed replacement of essential configuration content can soft-brick an intelligent electronic device, preventing normal restart, remote communications, and local recovery through the human-machine interface. Under some conditions, exploitation may also permit an attacker to take control of the node.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability in ABB equipment for which a variant was reportedly exploited in attacks impacting Poland’s electric grid-related targets, with discussion emphasizing device-bricking risk.
An improper handling of exceptional conditions vulnerability in ABB/Hitachi Relion IED equipment where deleting critical configuration files via FTP can leave the device unable to restart properly, disabling protection/control functions and remote/local recovery.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.