CVE-2020-8478
ABB System 800xA Inter process communication vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Insufficient protection of the inter-process communication functions in ABB System 800xA products OPC Server for AC 800M, MMS Server for AC 800M and Base Software for SoftControl (all published versions) enables an attacker authenticated on the local system to inject data, affecting the online view of runtime data shown in Control Builder.
Una protección insuficiente de las funciones de comunicación entre procesos en los productos OPC Server para AC 800M, MMS Server para AC 800M y Base Software para SoftControl (todas las versiones publicadas) de ABB System 800xA, permite a un atacante autenticado en el sistema local inyectar datos, afectando la visualización en línea de los datos del tiempo de ejecución que se muestran en Control Builder.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-30 CVE Reserved
- 2020-04-29 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Abb Search vendor "Abb" | Mms Server Search vendor "Abb" for product "Mms Server" | * | - |
Affected
| in | Abb Search vendor "Abb" | Ac800m Search vendor "Abb" for product "Ac800m" | - | - |
Safe
|
Abb Search vendor "Abb" | Opc Server Search vendor "Abb" for product "Opc Server" | * | - |
Affected
| in | Abb Search vendor "Abb" | Ac800m Search vendor "Abb" for product "Ac800m" | - | - |
Safe
|
Abb Search vendor "Abb" | Base Software Search vendor "Abb" for product "Base Software" | * | softcontrol |
Affected
|