← Back

CVE-2020-8472

nvd nist
Published: Apr 29, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Insufficient folder permissions used by system functions in ABB System 800xA products OPCServer for AC800M (versions 6.0 and earlier) and Control Builder M Professional, MMSServer for AC800M, Base Software for SoftControl (version 6.1 and earlier) allow low privileged users to read, modify, add and delete system and application files. An authenticated attacker who successfully exploited the vulnerabilities could escalate his/her privileges, cause system functions to stop and to corrupt user applications.

Affected (4)

4 products
Control Builder M
Mms Server
Opc Server
Base Software
Configuration A
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 6.1
Up to 6.1
Up to 6.0
Running on/withPlatform Versions
Abb
Ac800m
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 6.1

Timeline

No history available yet.