Back to Feed
VulnerabilitiesAug 6, 2026

ABB Ability Zenon

Multiple vulnerabilities in ABB Ability Zenon IIoT services with MongoDB (4.2) could allow attackers to bypass security

Summary

ABB Ability Zenon's IIoT services, when using MongoDB version 4.2, are affected by numerous vulnerabilities. These flaws could allow attackers to bypass security measures, crash systems, execute unauthorized actions, or compromise data. ABB recommends replacing the bundled MongoDB with a supported version or uninstalling IIoT services if not required.

Full text

ICS Advisory ABB Ability Zenon Release DateAugust 06, 2026 Alert CodeICSA-26-218-01 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data into Unsafe Value, Undefined Behavior for Input to API, Incorrect Regular Expression, Uncaught Exception, Reachable Assertion, Allocation of Resources Without Limits or Throttling, Out-of-bounds Write, Improper Output Neutralization for Logs, Improper Certificate Validation, Execution with Unnecessary Privileges Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-14847 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-130 Improper Handling of Length Parameter Inconsistency Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2020-7928 A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-158 Improper Neutralization of Null Byte or NUL Character Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2020-7921 Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3 and MongoDB Server v3.6 versions prior to 3.6.18. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , A

Indicators of Compromise

  • cve — CVE-2025-14847
  • cve — CVE-2020-7928
  • cve — CVE-2020-7921
  • cve — CVE-2020-7925
  • cve — CVE-2020-7929
  • cve — CVE-2020-7923
  • cve — CVE-2021-20330
  • cve — CVE-2021-32036
  • cve — CVE-2021-32040
  • cve — CVE-2021-20333
  • cve — CVE-2020-7924
  • cve — CVE-2021-20328
  • cve — CVE-2021-20334

Entities

ABB Ability Zenon (product)ABB (vendor)MongoDB (technology)