|
197831
|
7.5 |
HIGH
Network
|
abb
|
control_builder_safe 800xa_system compact_hmi
|
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Sa…
|
CWE-20
Improper Input Validation
|
CVE-2020-8475
|
2024-11-21 14:38 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197832
|
7.8 |
HIGH
Local
|
abb
|
control_builder_safe 800xa_system compact_hmi
|
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Sa…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8471
|
2024-11-21 14:38 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197833
|
7.8 |
HIGH
Local
|
abb
|
control_builder_m mms_server opc_server base_software
|
Insufficient folder permissions used by system functions in ABB System 800xA products OPCServer for AC800M (versions 6.0 and earlier) and Control Builder M Professional, MMSServer for AC800M, Base So…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-8472
|
2024-11-21 14:38 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197834
|
8.8 |
HIGH
Network
|
abb
|
800xa_information_manager
|
The installations for ABB System 800xA Information Manager versions 5.1, 6.0 to 6.0.3.2 and 6.1 wrongly contain an auxiliary component. An attacker is able to use this for an XSS-like attack to an au…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8477
|
2024-11-21 14:38 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197835
|
7.8 |
HIGH
Local
|
abb
|
800xa_base_system
|
Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause…
|
CWE-269
Improper Privilege Management
|
CVE-2020-8474
|
2024-11-21 14:38 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197836
|
6.2 |
MEDIUM
Physics
|
bitdefender
|
antivirus_2020
|
A vulnerability in the improper handling of junctions in Bitdefender Antivirus Free can allow an unprivileged user to substitute a quarantined file, and restore it to a privileged location. This issu…
|
CWE-59
Link Following
|
CVE-2020-8099
|
2024-11-21 14:38 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197837
|
7.8 |
HIGH
Local
|
lenovo
|
vantage
|
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authe…
|
CWE-269
Improper Privilege Management
|
CVE-2020-8327
|
2024-11-21 14:38 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197838
|
5.5 |
MEDIUM
Local
|
lenovo
|
system_interface_foundation
|
A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed.
|
CWE-20
Improper Input Validation
|
CVE-2020-8324
|
2024-11-21 14:38 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197839
|
7.8 |
HIGH
Local
|
lenovo
|
system_interface_foundation
|
A privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that could allow an authenticated user to execute code with elevated privileges.
|
NVD-CWE-noinfo
|
CVE-2020-8319
|
2024-11-21 14:38 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197840
|
7.8 |
HIGH
Local
|
lenovo
|
system_interface_foundation
|
A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation prior to version that could allow an authenticated user to execute code with e…
|
NVD-CWE-noinfo
|
CVE-2020-8318
|
2024-11-21 14:38 |
2020-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|