• ABB Ability Zenon

    From Cisa Advisories@2:263/1 to All on Thu Aug 6 18:03:08 2026
    ABB Ability Zenon

    View CSAF
    Summary
    Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data.
    The following versions of ABB Ability Zenon are affected:

    IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/*





    CVSS
    Vendor
    Equipment
    Vulnerabilities




    v3 7.8
    ABB
    ABB Ability Zenon
    Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data into Unsafe Value, Undefined Behavior for Input to API, Incorrect Regular Expression, Uncaught Exception, Reachable Assertion, Allocation of Resources Without Limits or Throttling, Out-of-bounds Write, Improper Output Neutralization for Logs, Improper Certificate Validation, Execution with Unnecessary Privileges




    Background

    Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater
    Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland


    Vulnerabilities

    Expand All +

    CVE-2025-14847

    Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
    View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-130 Improper Handling of Length Parameter Inconsistency

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    7.5
    HIGH
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N


    4.0
    8.7
    HIGH
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N







    CVE-2020-7928

    A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20. View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-158 Improper Neutralization of Null Byte or NUL Character

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    6.5
    MEDIUM
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N







    CVE-2020-7921

    Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3 and MongoDB Server v3.6 versions prior to 3.6.18. View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-182 Collapse of Data into Unsafe Value

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    5.3
    MEDIUM
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N







    CVE-2020-7925

    Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9. View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-475 Undefined Behavior for Input to API

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    7.5
    HIGH
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H







    CVE-2020-7929

    A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.
    View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-185 Incorrect Regular Expression

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    6.5
    MEDIUM
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H







    CVE-2020-7923

    A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19. View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-248 Uncaught Exception

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    6.5
    MEDIUM
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H







    CVE-2021-20330

    An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9. View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-617 Reachable Assertion

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    6.5
    MEDIUM
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H







    CVE-2021-32036

    An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28
    View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    7.1
    HIGH
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H







    CVE-2021-32040

    It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB Server v4.4 versions prior to and including 4.4.28, MongoDB Server v5.0 versions prior to 5.0.4 and MongoDB Server v4.2 versions prior to 4.2.16. Workaround: >= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash. View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-787 Out-of-bounds Write

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    7.5
    HIGH
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H







    CVE-2021-20333

    Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10. View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-117 Improper Output Neutralization for Logs

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    5.3
    MEDIUM
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N







    CVE-2020-7924

    Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates. This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions prior to 3.6.21; 4.0 versions prior to 4.0.21; 4.2 versions prior to 4.2.11; 100 versions prior to 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.
    View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-295 Improper Certificate Validation

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    6.5
    MEDIUM
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N







    CVE-2021-20328

    Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server's certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CSFLE. The Java async, Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and Azure network fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don't use Field Level Encryption. View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-295 Improper Certificate Validation

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    6.8
    MEDIUM
    CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N







    CVE-2021-20334

    A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and later versions; 1.x versions prior to 1.25.0 on Windows.
    View CVE Details

    Affected Products
    ABB Ability Zenon

    Vendor:ABB
    Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/*
    Product Status:known_affected


    Remediations
    MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required:
    MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.
    MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentI
    D=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json

    Relevant CWE: CWE-250 Execution with Unnecessary Privileges

    Metrics




    CVSS Version
    Base Score
    Base Severity
    Vector String




    3.1
    7.8
    HIGH
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H








    Acknowledgments

    ABB PSIRT reported these vulnerabilities to CISA


    Legal Notice and Terms of Use
    This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).

    Recommended Practices
    CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices.
    CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices
    on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies
    for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation
    Strategies.
    Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
    No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

    Revision History

    Initial Release Date: 2026-07-30




    Date
    Revision
    Summary




    2026-07-30
    1
    Initial Publication


    2026-08-06
    2
    Initial Republication of ABB PSIRT 9AKK108472A9037




    Legal Notice and Terms of Use

    https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01

    2026-08-06 12:00 UTC

    --- BBBS/LiR v4.10 Toy-7
    * Origin: LISTS. from TCOB1 READ ONLY (2:263/1)