ABB Ability Zenon

Act NowCVSS 7.8ICS-CERT ICSA-26-218-01Jul 30, 2026
ABB
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

ABB Ability Zenon version 4.2 bundles MongoDB 4.2, which has reached end-of-life and contains multiple known security vulnerabilities (CWE-130, CWE-158, CWE-182, CWE-475, CWE-185, CWE-248, CWE-617, CWE-770, CWE-787, CWE-117, CWE-295, CWE-250). These vulnerabilities are actively being exploited. An attacker with local access or network access to the MongoDB instance could leverage these flaws to access sensitive information, cause denial of service, or disrupt system availability of IIoT Services that manage industrial process data and remote connectivity.

What this means
What could happen
An attacker with local access to a machine running ABB zenon could exploit vulnerabilities in the bundled end-of-life MongoDB to access sensitive data, disrupt system availability, or interfere with IIoT operations.
Who's at risk
Organizations using ABB Ability Zenon version 4.2 with IIoT Services enabled for industrial automation, data logging, or cloud connectivity should prioritize assessment. This affects engineering workstations, data aggregation servers, and any systems relying on the bundled MongoDB for process data storage or remote monitoring.
How it could be exploited
An attacker with local system access or ability to reach the MongoDB instance could exploit known vulnerabilities in MongoDB 4.2 (such as privilege escalation or injection flaws) to execute arbitrary operations, read sensitive configuration data, or cause denial of service on systems managing industrial processes through the IIoT Services component.
Prerequisites
  • Local access to the system running ABB zenon with IIoT Services enabled
  • Network access to the MongoDB instance (typically localhost unless configured otherwise)
  • Knowledge of MongoDB 4.2 vulnerabilities and exploitation techniques
actively exploited (KEV)high EPSS score (83.0%)no patch available from vendoraffects IIoT/cloud integration systemsend-of-life component
Exploitability
Actively exploited — confirmed by CISA KEV
Metasploit module available — weaponized exploitView module ↗
Public Proof-of-Concept (PoC) on GitHub (10 repositories)
Affected products (1)
ProductAffected VersionsFix Status
Ability Zenon /all4.2No fix yet
Remediation & Mitigation
0/3
Do now
0/2
HARDENINGIf IIoT Services are not required, uninstall the IIoT Services component using the Control Panel uninstaller to remove the vulnerable MongoDB dependency entirely
HARDENINGRestrict network access to the MongoDB instance to only authorized systems and legitimate IIoT components using firewall rules or network segmentation
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXIf IIoT Services are required, replace the bundled MongoDB 4.2 with a supported and patched version through manual configuration as documented in the zenon online help
API: /api/v1/advisories/ca605bf3-87a6-487a-84bb-433d5cec663e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.