Loading vulnerabilities…
Loading vulnerabilities…
CVE-2025-14847
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
This record: live connection— last retrieved: 24 September 2026 at 05:11.
Taken directly from NVD, CISA or the vendor — sometimes in English, unchanged from the source.
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack vector
NETWORK
Privileges required
NONE
User interaction
NONE
Confidentiality
High
Integrity
None
Availability
None
Probability of exploitation within 30 days
83.2%
Percentile
100e
Source: FIRST.org, updated on 23 September 2026.
ABB recommends the following mitigation measures: - Replace bundled MongoDB with a supported version if IIoT services are required: - Where IIoT functionality is required, the bundled MongoDB instance can be replaced with a supported and patched version through manual configuration. - The following zenon online help section explains the process of installing and using your own MongoDB database: zenHelpViewer - Uninstall IIoT Services wherever it’s not required: - If IIoT Services are not required, they can be removed using the Control panel uninstaller. This eliminates the dependency on MongoDB without affecting other zenon components. Refer to section “General security recommendations” for further advise on how to keep your system secure.
Our own interpretation and context for the source data above.
IACS Radar assessment
Our own interpretation and context for this vulnerability — not an official source.
IACS Radar priority score
Based on CVSS 7.5, EPSS 83.2%, industrial relevance 65/100; raised due to confirmed active exploitation (KEV).
Combines CVSS, EPSS, KEV status, industrial relevance and exposure relevance — a complement to, not a replacement for, the individual scores below and above.
Conditions for exploitation
Operational impact & energy relevance
Limited impact on availability; the risk lies mainly with confidentiality or integrity of process data.
Assessed as relevant to the energy sector based on: Vermeld in een officiële CISA ICS Advisory, wat directe relevantie voor industriële besturingssystemen bevestigt. Vendor "ABB" is a known supplier of equipment for the energy sector. Included in the CISA KEV catalogue: confirmed evidence of actual exploitation.
Additional mitigations
Recommended defensive measures
Industrial relevance score
Automatically classified as industrially relevant based on CISA/NVD signals (see reasons).
Classified by IACS Radar-analysepijplijn (geautomatiseerd) on 24 September 2026.
IEC 62443 mapping
Automatic IACS Radar assessment based on the reported CWE weakness classification; not an official certification statement.