CVE-2020-8472 describes insufficient folder permissions in several ABB System 800xA products, including OPCServer for AC800M (v6.0 and earlier), Control Builder M Professional, MMSServer for AC800M, and Base Software for SoftControl (v6.1 and earlier). This vulnerability allows low-privileged authenticated users to read, modify, add, and delete system and application files. With a CVSS score of 7.8 (High), successful exploitation could lead to privilege escalation, system function disruption, and corruption of user applications. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.1CPE matchmatch criteria | cpe:2.3:a:abb:control_builder_m:*:*:*:*:professional:*:*:* | ||
<= 6.1CPE matchmatch criteria | cpe:2.3:a:abb:mms_server:*:*:*:*:*:*:*:* | ||
<= 6.0CPE matchmatch criteria | cpe:2.3:a:abb:opc_server:*:*:*:*:*:*:*:* | ||
<= 6.1CPE matchmatch criteria | cpe:2.3:a:abb:base_software:*:*:*:*:*:softcontrol:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.