CVE Vulnerabilities

CVE-2020-8482

Insecure Storage of Sensitive Information

Published: May 29, 2020 | Modified: Jun 01, 2020
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Insecure storage of sensitive information in ABB Device Library Wizard versions 6.0.X, 6.0.3.1 and 6.0.3.2 allows unauthenticated low privilege user to read file that contains confidential data

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Device_library_wizard Abb 6.0.0 (including) 6.0.3.2 (including)
Device_library_wizard Abb 6.1.0 (including) 6.1.0 (including)

References