Embedded MongoDB Leaves Zenon Users Exposed

The exposed part is the bundled MongoDB inside ABB Ability Zenon IIoT services, not just the Zenon application around it. A Zenon patch alone may leave the database component in place, so the vulnerable piece can stay exposed after the host software looks current. CISA maps ABB Ability Zenon IIoT services with MongoDB 4.2 to CVE-2025-14847, a Zlib header length mismatch that can let an unauthenticated client read uninitialized heap memory. The advisory also says successful exploitation can bypass security, crash systems, execute unauthorized actions, or compromise data. That matters for critical-infrastructure environments because the fix may sit in the embedded component, not the main product operators normally track. If IIoT services remain installed, the risk can persist even after the usual application update cycle.

Sources