CISA Advises on Multiple Vulnerabilities in ABB Ability Zenon IIoT Services
CISA has issued an advisory detailing multiple critical vulnerabilities affecting ABB Ability Zenon's IIoT services, which could lead to significant security bypasses, system instability, and data compromise.

The Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory highlighting a series of vulnerabilities impacting ABB Ability Zenon's Industrial Internet of Things (IIoT) services, particularly those utilizing MongoDB version 4.2. These flaws, if exploited, could allow attackers to bypass security measures, cause system crashes, execute unauthorized actions, or lead to the compromise of sensitive data. The advisory affects all versions of ABB Ability Zenon where IIoT services with MongoDB 4.2 are installed.
Several specific vulnerabilities have been identified, including issues related to improper handling of length parameters, null byte inconsistencies, data collapse into unsafe values, undefined behavior for API inputs, incorrect regular expression processing, uncaught exceptions, resource allocation without limits, out-of-bounds writes, and improper certificate validation. One notable vulnerability, CVE-2025-14847, involves mismatched length fields in Zlib compressed protocol headers, potentially allowing an unauthenticated client to read uninitialized heap memory. Another, CVE-2020-7928, permits an authorized user to trigger a read overrun and access arbitrary memory through specially crafted queries.
The potential impact of these vulnerabilities is significant, given the critical infrastructure sectors where ABB Ability Zenon is deployed. These include Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, and Water and Wastewater. The software is deployed worldwide, meaning the potential attack surface is extensive. Successful exploitation could disrupt operations, compromise sensitive industrial data, or provide a foothold for further network intrusion.
ABB has provided specific mitigation strategies to address these risks. For users requiring IIoT functionality, the primary recommendation is to replace the bundled MongoDB instance with a supported and patched version through manual configuration. Guidance on this process is available in the zenon online help documentation. Alternatively, if IIoT Services are not required for specific deployments, ABB advises uninstalling them entirely via the Control Panel uninstaller. This action eliminates the dependency on the vulnerable MongoDB component without affecting other zenon functionalities.
Beyond these direct actions, ABB also refers users to its "General security recommendations" for broader advice on maintaining system security. For more detailed information, ABB has issued its own PSIRT security advisories, available in both PDF and CSAF (Cybersecurity Asset Management Framework) formats. These advisories provide in-depth technical details and further guidance for customers.
The vulnerabilities carry high CVSS scores, with one rated at 7.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) and another at 8.7 HIGH (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N). Another identified vulnerability, CVE-2020-7921, related to improper serialization in the authorization subsystem, is rated 6.5 MEDIUM (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
This advisory underscores the ongoing challenges in securing Industrial Control Systems (ICS) and IIoT environments, where legacy components and third-party software integrations can introduce complex vulnerabilities. The reliance on specific versions of databases like MongoDB, as seen here, highlights the need for diligent patch management and regular security assessments within these critical operational technology (OT) environments.