CVE-2020-8474
published 2020-04-22CVE-2020-8474: Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality…
PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
20.4th percentile
Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | 800xa_base_system | <= 6.0.0 | — |
| abb | system_800xa_base | unspecified – 6.0 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB System 800xA Base
cisa_ics·2020-06-02·CVSS 7.8
[HIGH] ABB System 800xA Base
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB System 800xA Base
Last RevisedJune 02, 2020
Alert CodeICSA-20-154-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low skill level to exploit
- Vendor: ABB
- Equipment: System 800xA Base
- Vulnerability: Incorrect Permission Assignment for Critical Resource
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to escalate privileges and cause system functions to stop or malfunction.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of System 800xA Base are affected:
- System 800xA Base: Versions 6.0 a
GHSA
GHSA-wmcj-w5p4-34v2: Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functiona
ghsa_unreviewed·2022-05-24
CVE-2020-8474 [MEDIUM] GHSA-wmcj-w5p4-34v2: Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functiona
Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-22
Published