CVE-2020-8478

MEDIUM

ABB System 800xA OPC/MMS Server & Base Software - Authenticated Data Injection via IPC

Title source: llm
STIX 2.1

Description

Insufficient protection of the inter-process communication functions in ABB System 800xA products OPC Server for AC 800M, MMS Server for AC 800M and Base Software for SoftControl (all published versions) enables an attacker authenticated on the local system to inject data, affecting the online view of runtime data shown in Control Builder.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 16.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-74 CWE-264
Status published
Products (3)
abb/base_software
abb/mms_server
abb/opc_server
Published Apr 29, 2020
Tracked Since Feb 18, 2026