CVE-2020-8473
published 2020-04-29CVE-2020-8473: Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low privileged users to read, modify, add and…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
19.8th percentile
Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low privileged users to read, modify, add and delete system and application files. An authenticated attacker who successfully exploit the vulnerabilities could escalate his/her privileges, cause system functions to stop and to corrupt user applications.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | 800xa_base_system | <= 6.1 | — |
| abb | system_800xa_base | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:L/AC:L/Au:N/C:P/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xphv-67vw-89c5: Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6
ghsa_unreviewed·2022-05-24
CVE-2020-8473 [MEDIUM] GHSA-xphv-67vw-89c5: Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6
Insufficient folder permissions used by system functions in ABB System 800xA Base (version 6.1 and earlier) allow low privileged users to read, modify, add and delete system and application files. An authenticated attacker who successfully exploit the vulnerabilities could escalate his/her privileges, cause system functions to stop and to corrupt user applications.
CISA ICS
ABB System 800xA
cisa_ics·2020-06-02·CVSS 5.5
[MEDIUM] ABB System 800xA
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB System 800xA
Last RevisedJune 02, 2020
Alert CodeICSA-20-154-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.3
- ATTENTION: Low skill level to exploit
- Vendor: ABB
- Equipment: System 800xA
- Vulnerabilities: Incorrect Default Permissions
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges, cause system functions to stop, and corrupt user applications.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following products of System 800xA are affected:
- OPC Server for AC 800M: Versions 6.0 and prior
- Cont
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-29
Published