CVE-2020-8478
ABB System 800xA Inter process communication vulnerability
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
29 Apr 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Insufficient protection of the inter-process communication functions in ABB System 800xA products OPC Server for AC 800M, MMS Server for AC 800M and Base Software for SoftControl (all published versions) enables an attacker authenticated on the local system to inject data, affecting the online view of runtime data shown in Control Builder.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
ABB · Base Software for SoftControlABB · MMS Server for AC 800MABB · OPC Server for AC 800MWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →