Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RVD#3318: XSS-like attacks for authenticated users in ABB System 800xA Information Manager #3318

Open
rvd-bot opened this issue Jul 4, 2020 · 0 comments
Labels
components software Vulnerabilities in purely software robot components (e.g. a the ROS navigation stack) severity: high 7.0 - 8.9 vendor: ABB vulnerability

Comments

@rvd-bot
Copy link
Contributor

rvd-bot commented Jul 4, 2020

id: 3318
title: 'RVD#3318: XSS-like attacks for authenticated users in ABB System 800xA Information Manager'
type: vulnerability
description: The installations for ABB System 800xA Information Manager versions 5.1,
  6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able
  to use this for an XSS-like attack to an authenticated local user, which might lead
  to execution of arbitrary code.
cwe: CWE-79
cve: CVE-2020-8477
keywords: ''
system: 'ABB System 800xA Information Manager'
vendor: ABB
severity:
  rvss-score: 0
  rvss-vector: ''
  severity-description: 'high'
  cvss-score: 8.8
  cvss-vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
links:
- https://nvd.nist.gov/vuln/detail/CVE-2020-8477
- https://vulners.com/cve/CVE-2020-8477
- https://github.com/aliasrobotics/RVD/issues/3318
flaw:
  phase: unknown
  specificity: N/A
  architectural-location: N/A
  application: N/A
  subsystem: N/A
  package: N/A
  languages: None
  date-detected: '2020-04-22'
  detected-by: ''
  detected-by-method: N/A
  date-reported: '2020-07-04'
  reported-by: ''
  reported-by-relationship: N/A
  issue: https://github.com/aliasrobotics/RVD/issues/3318
  reproducibility: ''
  trace: ''
  reproduction: ''
  reproduction-image: ''
exploitation:
  description: ''
  exploitation-image: ''
  exploitation-vector: ''
  exploitation-recipe: ''
mitigation:
  description: ''
  pull-request: ''
  date-mitigation: ''
@rvd-bot rvd-bot changed the title The installations for ABB System 800xA Information Manager versio RVD#3318: The installations for ABB System 800xA Information Manager versio Jul 4, 2020
@vmayoral vmayoral changed the title RVD#3318: The installations for ABB System 800xA Information Manager versio RVD#3318: XSS-like attacks for authenticated users in ABB System 800xA Information Manager Jul 4, 2020
@vmayoral vmayoral added components software Vulnerabilities in purely software robot components (e.g. a the ROS navigation stack) vendor: ABB severity: high 7.0 - 8.9 labels Jul 4, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
components software Vulnerabilities in purely software robot components (e.g. a the ROS navigation stack) severity: high 7.0 - 8.9 vendor: ABB vulnerability
Projects
None yet
Development

No branches or pull requests

2 participants