VulnerabilityModified
CVE-2020-8477
An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.
HIGH 8.8EPSS 1.71%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.71% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-489
- Affected
- abb/800xa information manager
- Source
- cybersecurity@ch.abb.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.