First published: Fri May 29 2020(Updated: )
Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
ABB Device Library Wizard | >=6.0.0<=6.0.3.2 | |
ABB Device Library Wizard | =6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8482 is considered a high severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2020-8482, upgrade ABB Device Library Wizard to version 6.1.0 or later.
CVE-2020-8482 risks the exposure of confidential data due to insecure storage vulnerabilities.
Users of ABB Device Library Wizard versions 6.0.X, 6.0.3.1, 6.0.3.2, and 6.1.0 are affected by CVE-2020-8482.
Yes, unauthenticated low privilege users can exploit CVE-2020-8482 to read the file containing sensitive information.