ID

VAR-202004-2165


CVE

CVE-2020-8486


TITLE

ABB System 800xA RNRP Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-005048

DESCRIPTION

Insufficient protection of the inter-process communication functions in ABB System 800xA RNRP (all published versions) enables an attacker authenticated on the local system to inject data, affect node redundancy handling. ABB System 800xA RNRP There is an unspecified vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be put into a state. ABB System 800xA RNRP is a redundant network routing protocol used in ABB System 800xA distributed control system by Swiss ABB company. ABB System 800xA RNRP (all versions) has a vulnerability in permissions and access control issues

Trust: 2.7

sources: NVD: CVE-2020-8486 // JVNDB: JVNDB-2020-005048 // CNVD: CNVD-2020-27095 // IVD: b72df7f5-1872-4f76-b50e-aa8338e26f06 // IVD: ec13e7f9-33d1-4526-b971-aa8b53dffd8f // VULHUB: VHN-186611 // VULMON: CVE-2020-8486

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 1.0

sources: IVD: b72df7f5-1872-4f76-b50e-aa8338e26f06 // IVD: ec13e7f9-33d1-4526-b971-aa8b53dffd8f // CNVD: CNVD-2020-27095

AFFECTED PRODUCTS

vendor:abbmodel:system 800xa rnrpscope: - version: -

Trust: 1.4

vendor:abbmodel:800xa rnrpscope:eqversion:*

Trust: 1.1

vendor:800xa rnrpmodel: - scope:eqversion:*

Trust: 0.4

sources: IVD: b72df7f5-1872-4f76-b50e-aa8338e26f06 // IVD: ec13e7f9-33d1-4526-b971-aa8b53dffd8f // CNVD: CNVD-2020-27095 // VULMON: CVE-2020-8486 // JVNDB: JVNDB-2020-005048 // NVD: CVE-2020-8486

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-8486
value: HIGH

Trust: 1.0

cybersecurity@ch.abb.com: CVE-2020-8486
value: MEDIUM

Trust: 1.0

NVD: JVNDB-2020-005048
value: HIGH

Trust: 0.8

CNVD: CNVD-2020-27095
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202004-2374
value: HIGH

Trust: 0.6

IVD: b72df7f5-1872-4f76-b50e-aa8338e26f06
value: HIGH

Trust: 0.2

IVD: ec13e7f9-33d1-4526-b971-aa8b53dffd8f
value: HIGH

Trust: 0.2

VULHUB: VHN-186611
value: MEDIUM

Trust: 0.1

VULMON: CVE-2020-8486
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-8486
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

NVD: JVNDB-2020-005048
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2020-27095
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: b72df7f5-1872-4f76-b50e-aa8338e26f06
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

IVD: ec13e7f9-33d1-4526-b971-aa8b53dffd8f
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

VULHUB: VHN-186611
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-8486
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

cybersecurity@ch.abb.com: CVE-2020-8486
baseSeverity: MEDIUM
baseScore: 6.6
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 4.7
version: 3.1

Trust: 1.0

NVD: JVNDB-2020-005048
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: IVD: b72df7f5-1872-4f76-b50e-aa8338e26f06 // IVD: ec13e7f9-33d1-4526-b971-aa8b53dffd8f // CNVD: CNVD-2020-27095 // VULHUB: VHN-186611 // VULMON: CVE-2020-8486 // JVNDB: JVNDB-2020-005048 // CNNVD: CNNVD-202004-2374 // NVD: CVE-2020-8486 // NVD: CVE-2020-8486

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.0

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2020-005048 // NVD: CVE-2020-8486

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202004-2374

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-202004-2374

CONFIGURATIONS

sources: JVNDB: JVNDB-2020-005048

PATCH

title:SECURITY Interprocess communication vulnerability in System 800xAurl:https://search.abb.com/library/Download.aspx?DocumentID=2PAA121236&LanguageCode=en&DocumentPartId=&Action=Launch

Trust: 0.8

sources: JVNDB: JVNDB-2020-005048

EXTERNAL IDS

db:NVDid:CVE-2020-8486

Trust: 3.6

db:ICS CERTid:ICSA-20-154-03

Trust: 1.4

db:CNVDid:CNVD-2020-27095

Trust: 1.1

db:CNNVDid:CNNVD-202004-2374

Trust: 1.1

db:JVNid:JVNVU94921886

Trust: 0.8

db:JVNDBid:JVNDB-2020-005048

Trust: 0.8

db:AUSCERTid:ESB-2020.1923

Trust: 0.6

db:IVDid:B72DF7F5-1872-4F76-B50E-AA8338E26F06

Trust: 0.2

db:IVDid:EC13E7F9-33D1-4526-B971-AA8B53DFFD8F

Trust: 0.2

db:VULHUBid:VHN-186611

Trust: 0.1

db:VULMONid:CVE-2020-8486

Trust: 0.1

sources: IVD: b72df7f5-1872-4f76-b50e-aa8338e26f06 // IVD: ec13e7f9-33d1-4526-b971-aa8b53dffd8f // CNVD: CNVD-2020-27095 // VULHUB: VHN-186611 // VULMON: CVE-2020-8486 // JVNDB: JVNDB-2020-005048 // CNNVD: CNNVD-202004-2374 // NVD: CVE-2020-8486

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2020-8486

Trust: 2.0

url:https://search.abb.com/library/download.aspx?documentid=2paa121236&languagecode=en&documentpartid=&action=launch

Trust: 1.7

url:https://www.us-cert.gov/ics/advisories/icsa-20-154-03

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2020-8486

Trust: 0.8

url:https://jvn.jp/vu/jvnvu94921886/index.html

Trust: 0.8

url:https://www.auscert.org.au/bulletins/esb-2020.1923/

Trust: 0.6

url:https://search.abb.com/library/download.aspx?documentid=2paa121236&languagecode=en&documentpartid=&action=launch

Trust: 0.1

url:https://cwe.mitre.org/data/definitions/.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2020-27095 // VULHUB: VHN-186611 // VULMON: CVE-2020-8486 // JVNDB: JVNDB-2020-005048 // CNNVD: CNNVD-202004-2374 // NVD: CVE-2020-8486

SOURCES

db:IVDid:b72df7f5-1872-4f76-b50e-aa8338e26f06
db:IVDid:ec13e7f9-33d1-4526-b971-aa8b53dffd8f
db:CNVDid:CNVD-2020-27095
db:VULHUBid:VHN-186611
db:VULMONid:CVE-2020-8486
db:JVNDBid:JVNDB-2020-005048
db:CNNVDid:CNNVD-202004-2374
db:NVDid:CVE-2020-8486

LAST UPDATE DATE

2024-11-23T21:35:51.629000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-27095date:2020-05-08T00:00:00
db:VULHUBid:VHN-186611date:2020-05-07T00:00:00
db:VULMONid:CVE-2020-8486date:2020-05-07T00:00:00
db:JVNDBid:JVNDB-2020-005048date:2020-06-10T00:00:00
db:CNNVDid:CNNVD-202004-2374date:2020-06-08T00:00:00
db:NVDid:CVE-2020-8486date:2024-11-21T05:38:55.743

SOURCES RELEASE DATE

db:IVDid:b72df7f5-1872-4f76-b50e-aa8338e26f06date:2020-04-28T00:00:00
db:IVDid:ec13e7f9-33d1-4526-b971-aa8b53dffd8fdate:2020-04-28T00:00:00
db:CNVDid:CNVD-2020-27095date:2020-05-08T00:00:00
db:VULHUBid:VHN-186611date:2020-04-29T00:00:00
db:VULMONid:CVE-2020-8486date:2020-04-29T00:00:00
db:JVNDBid:JVNDB-2020-005048date:2020-06-05T00:00:00
db:CNNVDid:CNNVD-202004-2374date:2020-04-28T00:00:00
db:NVDid:CVE-2020-8486date:2020-04-29T02:15:12.263