{
  "document": {
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "tlp": {
        "label": "WHITE"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "ABB is aware of publicly reported vulnerabilities affecting MongoDB 4.2, which is bundled within the IIoT Services of the affected product versions. MongoDB 4.2 has reached end-of-life and contains multiple known security vulnerabilities. An attacker who successfully exploits these vulnerabilities could potentially access sensitive information, cause denial of service, or disrupt system availability.",
        "title": "Summary"
      },
      {
        "category": "other",
        "text": "For additional instructions and support please contact your local ABB service organization. For contact information, see www.abb.com/contactcenters.\n\nInformation about ABB’s cyber security program and capabilities can be found at www.abb.com/cybersecurity.",
        "title": "Support"
      },
      {
        "category": "legal_disclaimer",
        "text": "The information in this document is subject to change without notice, and should not be construed as a commitment by ABB.\n\nABB provides no warranty, express or implied, including warranties of merchantability and fitness for a particular purpose, for the information contained in this document, and assumes no responsibility for any errors that may appear in this document. In no event shall ABB or any of its suppliers be liable for direct, indirect, special, incidental or consequential damages of any nature or kind arising from the use of this document, or from the use of any hardware or software described in this document, even if ABB or its suppliers have been advised of the possibility of such damages.\n\nThis document and parts hereof must not be reproduced or copied without written permission from ABB, and the contents hereof must not be imparted to a third party nor used for any unauthorized purpose.\n\nAll rights to registrations and trademarks reside with their respective owners.\n",
        "title": "Notice"
      },
      {
        "category": "other",
        "text": "The following should be taken into consideration when planning system protection.\n- Recognizing and familiarizing all parts of the system and the system's communication links.\n- Removing all unnecessary communication links in the system.\n- Rating the security level of remaining connections and improving them with applicable methods to reach the required security level.\n- Hardening the system by removing or deactivating all unused processes, communication ports, and services.\n- Checking that the whole system has valid backups available from all applicable parts.\n- Collecting and storing backups of the system components and keeping those up to date.\n- Removing all unnecessary user accounts.\n- Define the role-based access right and follow the principle of least privilege.\n- Defining password policies.\n- Changing default passwords and using strong passwords.\n- Checking that the link from a substation to an upper-level system uses strong encryption and authentication.\n- Segregating public networks (untrusted) from automation networks (trusted).\n- Segmenting traffic and networks.\n- Using firewalls and demilitarized zones.\n- Assessing and patching the system periodically.\n- Using malware protection in workstations and keeping those up to date.\n",
        "title": "General security recommendations"
      },
      {
        "category": "other",
        "text": "ABB has a rigorous internal cyber security continuous improvement process which involves regular testing with industry leading tools and periodic assessments to identify potential product issues. Occasionally an issue is determined to be a design or coding flaw with implications that may impact product cyber security.\n\nWhen a potential product vulnerability is identified or reported, ABB immediately initiates our vulnerability handling process. This entails validating if the issue is in fact a product issue, identifying root causes, determining what related products may be impacted, developing a remediation, and notifying end users and governmental organizations.\n\nThe resulting Cyber Security Advisory intends to notify customers of the vulnerability and provide details on which products are impacted, how to mitigate the vulnerability or explain workarounds that minimize the potential risk as much as possible. The release of a Cyber Security Advisory should not be misconstrued as an affirmation or indication of an active threat or ongoing campaign targeting the products mentioned here. If ABB is aware of any specific threats, it will be clearly mentioned in the communication.\n\nThe publication of this Cyber Security Advisory is an example of ABB’s commitment to the user community in support of this critical topic. Responsible disclosure is an important element in the chain of trust we work to maintain with our many customers. The release of an Advisory provides timely information which is essential to help ensure our customers are fully informed.",
        "title": "Purpose"
      },
      {
        "category": "faq",
        "text": "What causes this vulnerability?\n- The vulnerability is caused by the use of an outdated MongoDB 4.2 component, which contains known security weaknesses.\n\nWhat are IIoT Services?\n- IIoT Services are a set of distributed software components designed to enable industrial data collection, processing, and integration across multiple systems. They can be deployed on separate machines or in the cloud, and use web-based technologies to ensure easy access, interoperability, and support across different devices.\n\nWhat might an attacker use the vulnerability to do?\n- An attacker exploiting these vulnerabilities could read sensitive memory contents or crash the MongoDB service, causing denial of service. Since v4.2 is end of life and multiple CVEs have been disclosed publicly, exposed instances risk unauthenticated data exfiltration, not just downtime.\n\nHow could an attacker exploit this vulnerability?\n- An attacker could attempt to interact with the MongoDB service through network access or malicious input to exploit known vulnerabilities.\n\nCould this vulnerability be exploited remotely? \n- Yes, an attacker with network access to the affected system could attempt exploitation.\n\nCan functional safety be affected by an exploit of this vulnerability?\n- No direct impact on functional safety is expected. However, system availability may be affected.\n\nWhen this security advisory was issued, had this vulnerability been publicly disclosed?\n- Yes, the MongoDB 4.2 CVEs are publicly disclosed. However, zenon's specific exposure, bundling this vulnerable version has not itself been publicly disclosed; it was identified during this assessment.\n\nWhen this security advisory was issued, had ABB received any reports that this vulnerability was being exploited?\n- No, ABB had not received any information indicating that this vulnerability had been exploited when this security advisory was originally issued.\n",
        "title": "Frequently Asked Questions"
      }
    ],
    "publisher": {
      "category": "vendor",
      "name": "ABB PSIRT",
      "namespace": "https://www.abb.com/global/en/company/about/cybersecurity/alerts-and-notifications"
    },
    "references": [
      {
        "category": "self",
        "summary": "ABB CYBERSECURITY ADVISORY - PDF Version ",
        "url": "https://search.abb.com/library/Download.aspx?DocumentID=9AKK108472A9037&LanguageCode=en&DocumentPartId=pdf&Action=Launch"
      },
      {
        "category": "self",
        "summary": "ABB CYBERSECURITY ADVISORY - CSAF Version ",
        "url": "https://psirt.abb.com/csaf/2026/9akk108472a9037.json"
      }
    ],
    "title": "ABB AbilityTM zenon Security Risk Due to End-of-Life MongoDB Component",
    "tracking": {
      "current_release_date": "2026-07-30T00:30:00.000Z",
      "generator": {
        "date": "2026-07-30T13:23:44.353Z",
        "engine": {
          "name": "Secvisogram",
          "version": "2.6.7"
        }
      },
      "id": "9AKK108472A9037",
      "initial_release_date": "2026-07-30T00:30:00.000Z",
      "revision_history": [
        {
          "date": "2026-07-30T00:30:00.000Z",
          "legacy_version": "A",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version_range",
                "name": "/all",
                "product": {
                  "name": "ABB Ability Zenon /all",
                  "product_id": "AF1"
                }
              }
            ],
            "category": "product_name",
            "name": "Ability Zenon"
          }
        ],
        "category": "vendor",
        "name": "ABB"
      },
      {
        "branches": [
          {
            "category": "product_version",
            "name": "4.2",
            "product": {
              "name": "IIoT services with MongoDB 4.2",
              "product_id": "AF2"
            }
          }
        ],
        "category": "product_name",
        "name": "IIoT services with MongoDB"
      }
    ],
    "relationships": [
      {
        "category": "installed_on",
        "full_product_name": {
          "name": "IIoT services with MongoDB 4.2 installed on ABB Ability Zenon /all",
          "product_id": "RAV1"
        },
        "product_reference": "AF2",
        "relates_to_product_reference": "AF1"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2025-14847",
      "cwe": {
        "id": "CWE-130",
        "name": "Improper Handling of Length Parameter Inconsistency"
      },
      "notes": [
        {
          "category": "description",
          "text": "Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2025-14847 ",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14847"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.3,
            "environmentalSeverity": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 7.3,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2025-14847"
    },
    {
      "cve": "CVE-2020-7928",
      "cwe": {
        "id": "CWE-158",
        "name": "Improper Neutralization of Null Byte or NUL Character"
      },
      "notes": [
        {
          "category": "description",
          "text": "A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue affects MongoDB Server v4.4 versions prior to 4.4.1; MongoDB Server v4.2 versions prior to 4.2.9; MongoDB Server v4.0 versions prior to 4.0.20 and MongoDB Server v3.6 versions prior to 3.6.20",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2020-7928",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7928"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 6.4,
            "environmentalSeverity": "MEDIUM",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 6.4,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2020-7928"
    },
    {
      "cve": "CVE-2020-7921",
      "cwe": {
        "id": "CWE-182",
        "name": "Collapse of Data into Unsafe Value"
      },
      "notes": [
        {
          "category": "description",
          "text": "Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action. This issue affects MongoDB Server v4.2 versions prior to 4.2.3; MongoDB Server v4.0 versions prior to 4.0.15; MongoDB Server v4.3 versions prior to 4.3.3and MongoDB Server v3.6 versions prior to 3.6.18.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2020-7921",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7921"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 5.2,
            "environmentalSeverity": "MEDIUM",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 5.2,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2020-7921"
    },
    {
      "cve": "CVE-2020-7925",
      "cwe": {
        "id": "CWE-475",
        "name": "Undefined Behavior for Input to API"
      },
      "notes": [
        {
          "category": "description",
          "text": "Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2020-7925",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7925"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 7.3,
            "environmentalSeverity": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 7.3,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2020-7925"
    },
    {
      "cve": "CVE-2020-7929",
      "cwe": {
        "id": "CWE-185",
        "name": "Incorrect Regular Expression"
      },
      "notes": [
        {
          "category": "description",
          "text": "A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue affects MongoDB Server v3.6 versions prior to 3.6.21 and MongoDB Server v4.0 versions prior to 4.0.20.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2020-7929",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7929"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.4,
            "environmentalSeverity": "MEDIUM",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 6.4,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2020-7929"
    },
    {
      "cve": "CVE-2020-7923",
      "cwe": {
        "id": "CWE-248",
        "name": "Uncaught Exception"
      },
      "notes": [
        {
          "category": "description",
          "text": "A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2020-7923",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7923"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.4,
            "environmentalSeverity": "MEDIUM",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 6.4,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2020-7923"
    },
    {
      "cve": "CVE-2021-20330",
      "cwe": {
        "id": "CWE-617",
        "name": "Reachable Assertion"
      },
      "notes": [
        {
          "category": "description",
          "text": "An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This issue affects MongoDB Server v4.0 versions prior to 4.0.27; MongoDB Server v4.2 versions prior to 4.2.16; MongoDB Server v4.4 versions prior to 4.4.9.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2021-20330",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20330"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.4,
            "environmentalSeverity": "MEDIUM",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 6.4,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2021-20330"
    },
    {
      "cve": "CVE-2021-32036",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "An authenticated user without any specific authorizations may be able to repeatedly invoke the features command where at a high volume may lead to resource depletion or generate high lock contention. This may result in denial of service and in rare cases could result in id field collisions. This issue affects MongoDB Server v5.0 versions prior to and including 5.0.3; MongoDB Server v4.4 versions prior to and including 4.4.9; MongoDB Server v4.2 versions prior to and including 4.2.16 and MongoDB Server v4.0 versions prior to and including 4.0.28",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2021-32036",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32036"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 6.9,
            "environmentalSeverity": "MEDIUM",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 6.9,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2021-32036"
    },
    {
      "cve": "CVE-2021-32040",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the size of the stack frames used by that stage. If an attacker could cause such an aggregation to occur, they could maliciously crash MongoDB in a DoS attack. This vulnerability affects MongoDB Server v4.4 versions prior to and including 4.4.28, MongoDB Server v5.0 versions prior to 5.0.4 and MongoDB Server v4.2 versions prior to 4.2.16. Workaround: >= v4.2.16 users and all v4.4 users can add the --setParameter internalPipelineLengthLimit=50 instead of the default 1000 to mongod at startup to prevent a crash.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2021-32040",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32040"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "environmentalScore": 7.3,
            "environmentalSeverity": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 7.3,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2021-32040"
    },
    {
      "cve": "CVE-2021-20333",
      "cwe": {
        "id": "CWE-117",
        "name": "Improper Output Neutralization for Logs"
      },
      "notes": [
        {
          "category": "description",
          "text": "Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6 versions prior to 3.6.20; MongoDB Server v4.0 versions prior to 4.0.21 and MongoDB Server v4.2 versions prior to 4.2.10.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2021-20333",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20333"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "environmentalScore": 5.2,
            "environmentalSeverity": "MEDIUM",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 5.2,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2021-20333"
    },
    {
      "cve": "CVE-2020-7924",
      "cwe": {
        "id": "CWE-295",
        "name": "Improper Certificate Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates.This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions prior to 3.6.21; 4.0 versions prior to 4.0.21; 4.2 versions prior to 4.2.11; 100 versions prior to 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2020-7924",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7924"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "environmentalScore": 6.4,
            "environmentalSeverity": "MEDIUM",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 6.4,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2020-7924"
    },
    {
      "cve": "CVE-2021-20328",
      "cwe": {
        "id": "CWE-295",
        "name": "Improper Certificate Validation"
      },
      "notes": [
        {
          "category": "description",
          "text": "Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Java driver and the KMS service rendering Field Level Encryption ineffective. This issue was discovered during internal testing and affects all versions of the Java driver that support CSFLE. The Java async, Scala, and reactive streams drivers are not impacted. This vulnerability does not impact driver traffic payloads with CSFLE-supported key services originating from applications residing inside the AWS, GCP, and Azure network fabrics due to compensating controls in these environments. This issue does not impact driver workloads that don’t use Field Level Encryption.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2021-20328",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20328"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "ADJACENT_NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 6.6,
            "environmentalSeverity": "MEDIUM",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 6.6,
            "temporalSeverity": "MEDIUM",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2021-20328"
    },
    {
      "cve": "CVE-2021-20334",
      "cwe": {
        "id": "CWE-250",
        "name": "Execution with Unnecessary Privileges"
      },
      "notes": [
        {
          "category": "description",
          "text": "A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary software with the privileges of the user who is running MongoDB Compass. This issue affects: MongoDB Inc. MongoDB Compass 1.x version 1.3.0 on Windows and later versions; 1.x versions prior to 1.25.0 on Windows.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "RAV1"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "NVD - CVE-2021-20334",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-20334"
        }
      ],
      "remediations": [
        {
          "category": "mitigation",
          "details": "ABB recommends the following mitigation measures: \n- Replace bundled MongoDB with a supported version if IIoT services are required: \n-  Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration.\n-  The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer \n- Uninstall IIoT Services wherever it’s not required: \n-  If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. \n\nRefer to section “General security recommendations” for further advise on how to keep your system secure.",
          "product_ids": [
            "RAV1"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalScore": 7.6,
            "environmentalSeverity": "HIGH",
            "exploitCodeMaturity": "FUNCTIONAL",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "remediationLevel": "UNAVAILABLE",
            "reportConfidence": "CONFIRMED",
            "scope": "UNCHANGED",
            "temporalScore": 7.6,
            "temporalSeverity": "HIGH",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C",
            "version": "3.1"
          },
          "products": [
            "RAV1"
          ]
        }
      ],
      "title": "CVE-2021-20334"
    }
  ]
}