CVE-2020-8481
published 2020-04-29CVE-2020-8481: For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.81%
76.1th percentile
For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 and 6.2, AdvaBuild 3.7 SP1 and SP2, OPCServer for MOD 300 (non-800xA) 1.4, OPC Data Link 2.1 and 2.2, Knowledge Manager 8.0, 9.0 and 9.1, Manufacturing Operations Management 1812 and 1909, confidential data is written in an unprotected file. An attacker who successfully exploited this vulnerability could take full control of the computer.
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| abb | 800xa_system | — | — |
| abb | abb_ability_system_800xa | — | — |
| abb | abb_ability_system_800xa | — | — |
| abb | abb_ability_system_800xa | — | — |
| abb | advabuild | — | — |
| abb | advabuild | — | — |
| abb | advant_ocs_ac_100_ops_server | — | — |
| abb | advant_ocs_ac_100_ops_server | — | — |
| abb | advant_ocs_ac_100_ops_server | — | — |
| abb | advant_ocs_control_builder_a | — | — |
| abb | advant_ocs_control_builder_a | — | — |
| abb | central_licensing_system | >= 5.1 < 5* | 5* |
| abb | compact_hmi | — | — |
| abb | compact_hmi | — | — |
| abb | composer_ctk | — | — |
| abb | composer_ctk | — | — |
| abb | composer_harmony | — | — |
| abb | composer_harmony | — | — |
| abb | composer_harmony | — | — |
| abb | composer_melody | — | — |
| abb | composer_melody | 6 – 6.3 | — |
| abb | control_builder_safe | — | — |
| abb | control_builder_safe | — | — |
| abb | control_builder_safe | — | — |
| abb | harmony_opc_server_standalone | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
ABB Central Licensing System
cisa_ics·2020-06-02
ABB Central Licensing System
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB Central Licensing System
Last RevisedJune 02, 2020
Alert CodeICSA-20-154-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: ABB
- Equipment: Central Licensing System (CLS)
- Vulnerabilities: Information Exposure; Improper Restriction of XML External Entity Reference; Uncontrolled Resource Consumption; Permissions, Privilege, and Access Controls; Improper Access Control
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to take control of the affected system node rem
GHSA
GHSA-w8qc-fmpq-5gmp: For ABB products ABB Ability™ System 800xA and related system extensions versions 5
ghsa_unreviewed·2022-05-24
CVE-2020-8481 [HIGH] CWE-922 GHSA-w8qc-fmpq-5gmp: For ABB products ABB Ability™ System 800xA and related system extensions versions 5
For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 and 6.2, AdvaBuild 3.7 SP1 and SP2, OPCServer for MOD 300 (non-800xA) 1.4, OPC Data Link 2.1 and 2.2, Knowledge Manager 8.0, 9.0 and 9.1, Manufacturing Operations Management 1812 and 1909, confidential data is written in an unprotected file. An atta
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://search.abb.com/library/Download.aspx?DocumentID=2PAA121230&LanguageCode=en&DocumentPartId=&Action=Launchhttps://search.abb.com/library/Download.aspx?DocumentID=2PAA121231&LanguageCode=en&DocumentPartId=&Action=Launchhttps://search.abb.com/library/Download.aspx?DocumentID=2PAA121230&LanguageCode=en&DocumentPartId=&Action=Launchhttps://search.abb.com/library/Download.aspx?DocumentID=2PAA121231&LanguageCode=en&DocumentPartId=&Action=Launch
2020-04-29
Published