ABB Ability Zenon
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data into Unsafe Value, Undefined Behavior for Input to API, Incorrect Regular Expression, Uncaught Exception, Reachable Assertion, Allocation of Resources Without Limits or Throttling, Out-of-bounds Write, Improper Output Neutralization for Logs, Improper Certificate Validation, Execution with Unnecessary Privileges Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-14847 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. View CVE Details Affected Products ABB Ability Zenon Vendor: ABB Product Version: ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status: known_affected Remediations Mitigation ABB recommends the following specific miti
CSIRTS triage
- What
- Multiple vulnerabilities including improper handling of length parameters, null byte injection, out-of-bounds writes, and certificate validation failures in ABB Ability Zenon IIoT services.
- Who is affected
- All versions of ABB Ability Zenon with MongoDB 4.2 installed, affecting critical infrastructure sectors including chemical, communications, and manufacturing.
- Urgency
- Critical — actively exploited vulnerability affecting critical infrastructure with CVSS 7.8 and ability to crash systems or execute unauthorized actions.
- Action
- Apply available security updates from ABB immediately and review all deployed Zenon instances for exposure in critical infrastructure environments.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Ability Zenon
Get an email when a new Ability Zenon advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2025-14847Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.6% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-79281.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2020-79210.66% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-79251.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 74% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-79291.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2020-79231.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2021-203301.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2021-320361.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2021-320402.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 78% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2021-203331.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-14847 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-7928 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-7921 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-7925 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-7929 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-7923 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-20330 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-32036 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-32040 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-20333 | coverage & exploitation status | NVD · CVE.org |
| CVE-2020-7924 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-20328 | coverage & exploitation status | NVD · CVE.org |
| CVE-2021-20334 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from CISA Cybersecurity Advisories
- criticalJohnson Controls Inc. TL2802026-08-06
- criticalMedixant RadiAnt DICOM2026-08-06
- highCISA Adds One Known Exploited Vulnerability to Catalog2026-08-05
- criticalThermo Fisher Applied Biosystems Genetic Analyzers2026-08-04
- highCISA Adds Three Known Exploited Vulnerabilities to Catalog2026-08-04