The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.
2020-04-22T15:15:14.863
2024-11-21T05:38:54.967
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | abb | 800xa_information_manager | ≤ 6.0.3.2 | Yes |
Application | abb | 800xa_information_manager | 5.1 | Yes |
Application | abb | 800xa_information_manager | 6.1 | Yes |