CVE-2020-8477
Estado: ModificadaAlta (8.8)—
The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.71%
- Percentil entre todas las CVEs puntuadas: 77
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79, CWE-489
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-8477",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cybersecurity@ch.abb.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cybersecurity@ch.abb.com",
"affectedData": [
{
"vendor": "ABB",
"product": "System 800xA Information Manager",
"versions": [
{
"status": "affected",
"version": "5",
"versionType": "custom",
"lessThanOrEqual": "5.1"
},
{
"status": "affected",
"version": "6.0",
"versionType": "custom",
"lessThanOrEqual": "6.0.3.2"
},
{
"status": "affected",
"version": "6.1",
"lessThan": "6.1*",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-04-22T15:15:14.863",
"references": [
{
"url": "https://search.abb.com/library/Download.aspx?DocumentID=2PAA121232&LanguageCode=en&DocumentPartId=&Action=Launch",
"tags": [
"Vendor Advisory"
],
"source": "cybersecurity@ch.abb.com"
},
{
"url": "https://search.abb.com/library/Download.aspx?DocumentID=2PAA121232&LanguageCode=en&DocumentPartId=&Action=Launch",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cybersecurity@ch.abb.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
},
{
"lang": "en",
"value": "CWE-489"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an authenticated local user, which might lead to execution of arbitrary code."
},
{
"lang": "es",
"value": "Las instalaciones de ABB System 800xA Information Manager versiones 5.1, versiones 6.0 hasta 6.0.3.2 y versión 6.1, contienen incorrectamente un componente auxiliar. Un atacante puede usar esto para un ataque de tipo XSS hacia un usuario local autenticado, lo que podría conllevar a una ejecución de código arbitrario."
}
],
"lastModified": "2026-06-17T03:26:26.593",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:abb:800xa_information_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F4A08380-B93C-462D-8350-79C886FCF48C",
"versionEndIncluding": "6.0.3.2",
"versionStartIncluding": "6.0.0"
},
{
"criteria": "cpe:2.3:a:abb:800xa_information_manager:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5990ADCE-C4A5-4153-BE11-B877C23E0186"
},
{
"criteria": "cpe:2.3:a:abb:800xa_information_manager:6.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC39FF5F-DE4F-428D-984B-331CC501DC6D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cybersecurity@ch.abb.com"
}