SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-8477

An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.

HIGH 8.8EPSS 1.71%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
1.71% probability · 76th percentile
CISA KEV
Not listed
Weakness
CWE-79, CWE-489
Affected
abb/800xa information manager
Source
cybersecurity@ch.abb.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.