THEMETASEC

Cybersecurity News, Aggregated

ABB Ability Zenon

CISA Advisories · 6 hours ago Vuln

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/*  CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data into Unsafe Value, Undefined Behavior for Input to API, Incorrect Regular Expression, Uncaught Exception, Reachable Assertion, Allocation of Resources Without Limits or Throttling, Out-of-bounds Write, Improper Output Neutralization for Logs, Improper Certificate Validation, Execution with Unnecessary Privileges Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-14847 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-130 Improper Handling of Length Parameter Inconsistency Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2020-7928 A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-158 Improper Neutralization of Null Byte or NUL Character Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2020-7921 Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3 and MongoDB Server v3.6 versions prior to 3.6.18. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-182 Collapse of Data into Unsafe Value Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N CVE-2020-7925 Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-475 Undefined Behavior for Input to API Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-7929 A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-185 Incorrect Regular Expression Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2020-7923 A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-248 Uncaught Exception Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-20330 An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-617 Reachable Assertion Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2021-32036 An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28 View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-770 Allocation of Resources Without Limits or Throttling Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H CVE-2021-32040 It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB Server v4.4 versions prior to and including 4.4.28, MongoDB Server v5.0 versions prior to 5.0.4 and MongoDB Server v4.2 versions prior to 4.2.16. Workaround: >= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-20333 Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-117 Improper Output Neutralization for Logs Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVE-2020-7924 Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates. This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions prior to 3.6.21; 4.0 versions prior to 4.0.21; 4.2 versions prior to 4.2.11; 100 versions prior to 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-295 Improper Certificate Validation Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVE-2021-20328 Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server's certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CSFLE. The Java async, Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and Azure network fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don't use Field Level Encryption. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-295 Improper Certificate Validation Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-20334 A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and later versions; 1.x versions prior to 1.25.0 on Windows. View CVE Details Affected Products ABB Ability Zenon Vendor:ABB Product Version:ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status:known_affected Remediations MitigationABB recommends the following specific mitigations for users with IIoT services utilizing MongoDB (version 4.2) on ABB Ability Zenon to reduce risk: MitigationReplace bundled MongoDB with a supported version if IIoT services are required: MitigationWhere IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. MitigationThe following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer. MitigationUninstall IIoT Services wherever it's not required: MitigationIf IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section "General security recommendations" for further advice on how to keep your system secure. MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch MitigationFor more information see the associated ABB PSIRT security advisory 9AKK108472A9037 ABB CYBERSECURITY ADVISORY - PDF Version , ABB CYBERSECURITY ADVISORY - CSAF Version .https://psirt.abb.com/csaf/2026/9akk108472a9037.json Relevant CWE: CWE-250 Execution with Unnecessary Privileges Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Acknowledgments ABB PSIRT reported these vulnerabilities to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs). Recognize VPNs may have vulnerabilities, should be updated to the most recent version available, and are only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-07-30 Date Revision Summary 2026-07-30 1 Initial Publication 2026-08-06 2 Initial Republication of ABB PSIRT 9AKK108472A9037 Legal Notice and Terms of Use

Read full story at CISA Advisories →