Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-8477


The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.


Published

2020-04-22T15:15:14.863

Last Modified

2024-11-21T05:38:54.967

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-79
    CWE-489
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application abb 800xa_information_manager ≤ 6.0.3.2 Yes
Application abb 800xa_information_manager 5.1 Yes
Application abb 800xa_information_manager 6.1 Yes

References