ZeroHour

CVE-2020-8477

CVSS 3.1
8.8 high
EPSS
2%p76
Published
()
Modified
Description

The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.

Vendors
abb
Products
800xa information manager
Weakness
CWE-79, CWE-489
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.