CVE-2020-8478 MEDIUM

CVE-2020-8478: ABB System 800xA Inter process communication vulnerability

Vendor Abb
Product OPC Server for AC 800M
Weakness CWE-264
Published April 29, 2020
Last update August 4, 2024

CVSS base score

5.3/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Insufficient protection of the inter-process communication functions in ABB System 800xA products OPC Server for AC 800M, MMS Server for AC 800M and Base Software for SoftControl (all published versions) enables an attacker authenticated on the local system to inject data, affecting the online view of runtime data shown in Control Builder.

Key dates

02Disclosure timeline

April 29, 2020 CVE published
August 4, 2024 Record updated