VORANT. Threat Intelligence Sign in Get the full feed

ABB Zenon bundles vulnerable MongoDB 4.2

medium vulnerability energyhealthcaretelecommunicationstechnology

ABB Ability Zenon's bundled MongoDB 4.2 IIoT component carries over a dozen legacy MongoDB vulnerabilities allowing DoS, memory disclosure, or auth bypass.

CISA published an ICS advisory covering ABB Ability Zenon's IIoT services, which bundle an outdated MongoDB Server 4.2 instance. The advisory catalogs numerous legacy MongoDB CVEs spanning 2020-2021 (plus a 2025 wire-protocol parsing flaw), including uninitialized heap memory reads by unauthenticated clients, IP whitelist bypass following administrative action, denial-of-service via malformed queries/regex/aggregation pipelines, log injection, improper certificate validation, and local privilege execution via MongoDB Compass on Windows. None of these are new vulnerabilities in Zenon itself; rather, ABB shipped an end-of-life MongoDB version that inherits all of its historical unpatched issues.

Exploitation could allow attackers to bypass security controls, crash the database or dependent IIoT services, execute unauthorized actions, or access/corrupt data — impacts that could cascade into industrial control environments across chemical, energy, water/wastewater, healthcare, communications, and critical manufacturing sectors given zenon's worldwide deployment. There is no evidence of active exploitation; this is a vendor-disclosed component-dependency issue rather than a live campaign.

ABB recommends replacing the bundled MongoDB 4.2 with a supported, patched MongoDB version via manual configuration, or uninstalling IIoT Services entirely if not required, which removes the MongoDB dependency without affecting other zenon functionality. CISA reiterates standard ICS hardening guidance: minimize internet exposure of control system devices, segment control networks behind firewalls, and use VPNs with awareness of their own limitations for any required remote access.

Mentioned in this report

Vulnerabilities CVE-2020-7921CVE-2020-7923CVE-2020-7924CVE-2020-7925CVE-2020-7928CVE-2020-7929CVE-2021-20328CVE-2021-20330CVE-2021-20333CVE-2021-20334CVE-2021-32036CVE-2021-32040CVE-2025-14847KEV

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free