CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2021-20330

criticalcovered by 1 sourcefirst seen 2026-08-06
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to bypass security, crash systems, execute unauthorized actions, or compromise data. The following versions of ABB Ability Zenon are affected: IIoT services with MongoDB (4.2) installed on ABB Ability Zenon vers:all/* CVSS Vendor Equipment Vulnerabilities v3 7.8 ABB ABB Ability Zenon Improper Handling of Length Parameter Inconsistency, Improper Neutralization of Null Byte or NUL Character, Collapse of Data into Unsafe Value, Undefined Behavior for Input to API, Incorrect Regular Expression, Uncaught Exception, Reachable Assertion, Allocation of Resources Without Limits or Throttling, Out-of-bounds Write, Improper Output Neutralization for Logs, Improper Certificate Validation, Execution with Unnecessary Privileges Background Critical Infrastructure Sectors: Chemical, Communications, Critical Manufacturing, Dams, Energy, Healthcare and Public Health, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2025-14847 Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0. View CVE Details Affected Products ABB Ability Zenon Vendor: ABB Product Version: ABB IIoT services with MongoDB (4.2) installed on ABB Ability Zenon: vers:all/* Product Status: known_affected Remediations Mitigation ABB recommends the following specific miti

CSIRTS triage

What
Multiple vulnerabilities including improper handling of length parameters, null byte injection, out-of-bounds writes, and certificate validation failures in ABB Ability Zenon IIoT services.
Who is affected
All versions of ABB Ability Zenon with MongoDB 4.2 installed, affecting critical infrastructure sectors including chemical, communications, and manufacturing.
Urgency
Critical — actively exploited vulnerability affecting critical infrastructure with CVSS 7.8 and ability to crash systems or execute unauthorized actions.
Action
Apply available security updates from ABB immediately and review all deployed Zenon instances for exposure in critical infrastructure environments.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2021-20330

Get an email if CVE-2021-20330 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2021-20330

CVE.org record

Embed the live status

CVE-2021-20330 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2021-20330 status](https://www.csirts.com/badge/CVE-2021-20330)](https://www.csirts.com/cve/CVE-2021-20330)