CVE-2020-8478
3.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD
Description
Insufficient protection of the inter-process communication functions in ABB System 800xA products OPC Server for AC 800M, MMS Server for AC 800M and Base Software for SoftControl (all published versions) enables an attacker authenticated on the local system to inject data, affecting the online view of runtime data shown in Control Builder.
Affected (3)
Products: Abb: Mms Server, Opc Server, Base Software
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
| Running on/with | Platform Versions |
|---|---|
Abb Ac800m | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Related CWEs
CWE-264
CWE-264
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
References (2)
Source: cybersecurity@ch.abb.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.