First published: Wed Apr 22 2020(Updated: )
The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
ABB 800xA | >=6.0.0<=6.0.3.2 | |
ABB 800xA | =5.1 | |
ABB 800xA | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8477 is categorized as a medium severity vulnerability due to its potential to lead to arbitrary code execution via an XSS-like attack.
To mitigate CVE-2020-8477, upgrade your installation of ABB System 800xA Information Manager to a version that does not include the vulnerable auxiliary component.
CVE-2020-8477 affects ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2, and 6.1.
CVE-2020-8477 allows for an XSS-like attack that could lead to the execution of arbitrary code by an authenticated local user.
No, CVE-2020-8477 requires an authenticated local user to perform the exploit.