# Outdated MongoDB in ABB's Industrial Automation Platform Exposes Critical Infrastructure to Unauthenticated Attacks


## The Threat


ABB Ability Zenon — a widely deployed industrial automation and SCADA platform used in energy grids, water treatment facilities, chemical plants, and hospitals — ships with a bundled MongoDB 4.2 instance as part of its IIoT services component. That database is end-of-life, unpatched, and carrying vulnerabilities that allow unauthenticated remote attackers to read arbitrary heap memory and authorized users to trigger out-of-bounds reads that expose the contents of system memory.


The core problem isn't a novel attack technique. MongoDB 4.2 reached end-of-life in April 2024, and the vulnerabilities now surfacing in ABB's advisory span nearly six years of accumulated debt — including CVE-2020-7928, a flaw disclosed in 2020. ABB bundled the database, never updated it, and left operators with no automatic patch path. The only fix is manual: either swap in a supported MongoDB version yourself or uninstall IIoT Services entirely.


What makes this dangerous in an OT context is the combination of network-accessible exposure, unauthenticated triggering conditions, and the sensitivity of the environments these systems control. An attacker who can reach the MongoDB port on a Zenon IIoT server — common in poorly segmented industrial networks — can trigger a heap memory disclosure without any credentials. That information can then be used to fingerprint the host, leak configuration data, or inform follow-on exploitation. In operational technology environments where availability is paramount and patch windows are measured in months, that's a meaningful threat surface.


## Severity and Impact


| CVE | CVSS v3.1 | CVSS v4.0 | Severity | Vector | CWE |

|-----|-----------|-----------|----------|--------|-----|

| CVE-2025-14847 | 7.5 | 8.7 | HIGH | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | CWE-130 (Improper Handling of Length Parameter Inconsistency) |

| CVE-2020-7928 | — | — | HIGH | Network-accessible, authenticated user required | Out-of-bounds read / arbitrary memory access |


Additional vulnerability classes identified across the bundled MongoDB component include: null byte injection, unsafe value collapse, undefined API input behavior, regex flaws, uncaught exceptions, reachable assertions, resource exhaustion, out-of-bounds write, log output neutralization failures, improper certificate validation, and execution with unnecessary privileges. The overall vendor CVSS score across the advisory is 7.8 HIGH.


## Affected Products


ABB Ability Zenon — all versions with IIoT services utilizing MongoDB 4.2 installed:


  • MongoDB Server v4.2 (all versions ≥ 4.2.0) — end-of-life, no upstream patch available
  • MongoDB Server v4.0 (all versions ≥ 4.0.0) — similarly EOL
  • MongoDB Server v3.6 (all versions ≥ 3.6.0) — similarly EOL

  • For CVE-2025-14847 specifically, patched versions exist in currently supported MongoDB branches:

  • v7.0 < 7.0.28 (patched in 7.0.28)
  • v8.0 < 8.0.17 (patched in 8.0.17)
  • v8.2 < 8.2.3 (patched in 8.2.3)
  • v6.0 < 6.0.27 (patched in 6.0.27)
  • v5.0 < 5.0.32 (patched in 5.0.32)
  • v4.4 < 4.4.30 (patched in 4.4.30)

  • Deployed globally across: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, and Water and Wastewater sectors.


    ## Mitigations


    ABB has not released an updated Zenon package with a patched MongoDB. The remediation burden falls entirely on operators, with two paths:


    Option 1 — Replace the bundled MongoDB instance (if IIoT services are required):

  • Manually install a supported, patched MongoDB version (v6.0.27+, v7.0.28+, v8.0.17+, or v8.2.3+)
  • Reconfigure ABB Ability Zenon's IIoT services to use the external instance
  • Consult the zenon online help (zenHelpViewer) for the database swap procedure
  • Reference ABB PSIRT advisory 9AKK108472A9037 for detailed guidance

  • Option 2 — Uninstall IIoT Services (if IIoT functionality is not needed):

  • Remove IIoT Services via the Windows Control Panel uninstaller
  • This eliminates the MongoDB dependency entirely without affecting core zenon components
  • Recommended for any deployment where IIoT services are not actively used

  • Network-level controls (apply regardless of remediation path):

  • Restrict access to MongoDB ports (default: 27017) using firewall rules and network segmentation
  • Ensure Zenon servers are not directly internet-accessible
  • Apply the principle of least privilege to any accounts with database query access
  • Review ABB's general security recommendations in the advisory for further hardening guidance

  • ## References


  • ABB PSIRT Advisory 9AKK108472A9037 (PDF): [https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch](https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch)
  • ABB PSIRT Advisory (CSAF): [https://psirt.abb.com/csaf/2026/9akk108472a9037.json](https://psirt.abb.com/csaf/2026/9akk108472a9037.json)
  • NVD Entry CVE-2025-14847: https://nvd.nist.gov/vuln/detail/CVE-2025-14847
  • NVD Entry CVE-2020-7928: https://nvd.nist.gov/vuln/detail/CVE-2020-7928

  • ---


    ## HackWire Analysis


    The deeper story here isn't really about MongoDB heap reads — it's about a structural failure in how ICS vendors handle third-party software dependencies. ABB bundled MongoDB 4.2 into Ability Zenon and then, as MongoDB's own end-of-life clock ran down and vulnerability disclosures piled up, apparently did nothing. CVE-2020-7928 was disclosed in 2020. It's now 2026. That's six years of a known, network-accessible memory disclosure vulnerability sitting inside industrial control systems at energy utilities and water treatment plants.


    This is the bundled-dependency trap in its worst form: the ICS vendor controls the packaging, the database vendor drops support, and the operator — who often can't patch anything without a change control process, a maintenance window, and sign-off from an OEM — is left holding a live vulnerability they didn't know they had. ABB's own fix guidance underscores the problem: there's no update package, no automated remediation. You either do a manual database swap by reading the help documentation, or you uninstall the feature entirely.


    For defenders, the priority filter here is simple: if you run ABB Ability Zenon with IIoT services enabled, check your MongoDB version today. If it's 4.2 (or anything in the 3.x/4.0.x/4.1.x range), treat that port as a live exposure and firewall it immediately while you work through the replacement process. Don't assume your OT network is too flat for attackers to reach it — lateral movement from IT to OT is a documented attacker technique, and a heap memory disclosure on a SCADA server is exactly the kind of reconnaissance step that precedes something worse.


    Broader lesson: every ICS procurement process should now include a software bill of materials requirement. If your automation vendor can't tell you what database engine version is running inside their platform, that's an unacceptable answer.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)