Multiple Vulnerabilities Discovered in ABB Ability Zenon IIoT Services with Bundled MongoDB
An advisory published by CISA and ABB PSIRT discloses multiple vulnerabilities in ABB Ability Zenon Industrial IoT services. The flaws involve CVE-2025-14847, a heap memory read issue in Zlib compressed protocol headers affecting all MongoDB versions prior to specified patch levels, and CVE-2020-7928, a memory read overrun affecting older MongoDB versions. Both vulnerabilities affect ABB Ability Zenon versions with MongoDB 4.2 installed and have been assigned CVSS scores up to 8.7. ABB recommends replacing the bundled MongoDB with a supported patched version or uninstalling IIoT services where not required.