CVE-2020-8482

HIGH

ABB Device Library Wizard <6.0.X - Info Disclosure

Title source: llm
STIX 2.1

Description

Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0007
EPSS Percentile 21.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-922
Status published
Products (2)
abb/device_library_wizard 6.1.0
abb/device_library_wizard 6.0.0 - 6.0.3.2
Published May 29, 2020
Tracked Since Feb 18, 2026