CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

ABB Ability Zenon

criticalknown exploitedpublic exploitCVE-2025-14847CVE-2020-7928CVE-2020-7921CVE-2020-7925CVE-2020-7929CVE-2020-7923
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data into Unsafe Value, Undefined Behavior for Input to API, Incorrect Regular Expression, Uncaught Exception, Reachable Assertion, Allocation of Resources Without Limits or Throttling, Out-of-bounds Write, Improper Output Neutralization for Logs, Improper Certificate Validation, Execution with Unnecessary Privileges Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-14847 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. View CVE Details Affected Products ABB Ability Zenon Vendor: ABB Product Version: ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status: known_affected Remediations Mitigation ABB recommends the following specific miti

CSIRTS triage

What
Multiple vulnerabilities including improper handling of length parameters, null byte injection, out-of-bounds writes, and certificate validation failures in ABB Ability Zenon IIoT services.
Who is affected
All versions of ABB Ability Zenon with MongoDB 4.2 installed, affecting critical infrastructure sectors including chemical, communications, and manufacturing.
Urgency
Critical — actively exploited vulnerability affecting critical infrastructure with CVSS 7.8 and ability to crash systems or execute unauthorized actions.
Action
Apply available security updates from ABB immediately and review all deployed Zenon instances for exposure in critical infrastructure environments.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Ability Zenon

Get an email when a new Ability Zenon advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-06
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-01

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-14847coverage & exploitation statusNVD · CVE.org
CVE-2020-7928coverage & exploitation statusNVD · CVE.org
CVE-2020-7921coverage & exploitation statusNVD · CVE.org
CVE-2020-7925coverage & exploitation statusNVD · CVE.org
CVE-2020-7929coverage & exploitation statusNVD · CVE.org
CVE-2020-7923coverage & exploitation statusNVD · CVE.org
CVE-2021-20330coverage & exploitation statusNVD · CVE.org
CVE-2021-32036coverage & exploitation statusNVD · CVE.org
CVE-2021-32040coverage & exploitation statusNVD · CVE.org
CVE-2021-20333coverage & exploitation statusNVD · CVE.org
CVE-2020-7924coverage & exploitation statusNVD · CVE.org
CVE-2021-20328coverage & exploitation statusNVD · CVE.org
CVE-2021-20334coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from CISA Cybersecurity Advisories