ABB Ability Zenon: MongoDB 4.2 Vulnerabilities Expose Industrial Systems

MongoDB 4.2 flaws in ABB Ability Zenon allow remote exploits, exposing industrial systems to outages and data breaches. No patches disclosed.

ABB Ability Zenon: MongoDB 4.2 Vulnerabilities Expose Industrial Systems
Vulnerabilities

Illustrative image generated with AI

ABB Ability Zenon with IIoT services affected

An advisory published on August 6, 2026 reports vulnerabilities in ABB Ability Zenon when the product includes IIoT services with MongoDB Server 4.2.

The affected product set includes all versions of ABB Ability Zenon (vers:all/*). The exposure is classified as known_affected and has a worldwide scope.

Potentially affected sectors include:

  • chemical;
  • communications;
  • critical manufacturing;
  • dams;
  • energy;
  • healthcare and public health;
  • information technology;
  • water and wastewater.

A successful attack could allow attackers to bypass security controls, cause system outages, perform unauthorized operations, or compromise data.

The most severe flaw can be exploited without authentication

CVE-2025-14847 concerns the handling of inconsistent length parameters (CWE-130). An unauthenticated client can send compressed Zlib headers with mismatched values and read data from uninitialized heap memory.

The issue affects MongoDB 4.2 from 4.2.0 onward, as well as versions prior to the fixes released for the 3.6, 4.0, 4.4, 5.0, 6.0, 7.0, 8.0, and 8.2 branches.

The severity is HIGH:

  • CVSS 3.1: 7.5;
  • CVSS 4.0: 8.7;
  • vector: remote attack, low complexity, no privileges required, and no user interaction.

The flaw primarily allows information to be read from memory. No direct impact on integrity or availability has been reported for this vulnerability.

Two other flaws affect authenticated users

CVE-2020-7928 (CWE-158) allows an authorized user who can run queries to trigger an out-of-bounds read through specially crafted queries. The attack may expose arbitrary memory.

The affected MongoDB versions are:

  • 4.4 prior to 4.4.1;
  • 4.2 prior to 4.2.9;
  • 4.0 prior to 4.0.20;
  • 3.6 prior to 3.6.20.

The CVSS 3.1 score is 6.5, rated MEDIUM.

CVE-2020-7921 (CWE-182) concerns serialization of the authorization subsystem’s internal state. After an administrative action, an authenticated user may bypass IP address whitelists.

The flaw affects MongoDB 4.2 prior to 4.2.3, as well as the 3.6, 4.0, and 4.3 branches in the specified versions. No CVSS score or vector has been disclosed for this vulnerability.

The advisory also associates the product with API input-handling errors, flawed regular expressions, uncaught exceptions, reachable assertions, unbounded allocations, buffer overflows, improperly sanitized log output, improper certificate validation, and execution with excessive privileges.

What administrators should check

No patches, fixed versions, or specific workarounds for ABB Ability Zenon have been disclosed. Administrators should therefore:

  1. inventory Zenon installations that include IIoT services;
  2. check whether MongoDB Server 4.2 is present;
  3. determine whether the database is reachable from unnecessary networks;
  4. restrict access to authorized hosts and reduce account privileges;
  5. monitor anomalous queries, unexpected Zlib requests, memory errors, and attempts to modify IP whitelists;
  6. wait for ABB’s remediation guidance before applying unverified updates.

The absence of a published fixed version makes network segmentation and reducing exposure of MongoDB services the top priorities.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →