CVE-2020-11639
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/07/2024
Last modified:
19/12/2025
Description
An attacker could exploit the vulnerability by<br />
injecting garbage data or specially crafted data. Depending on the data injected each process might be<br />
affected differently. The process could crash or cause communication issues on the affected node, effectively causing a denial-of-service attack. The attacker could tamper with the data transmitted, causing<br />
the product to store wrong information or act on wrong data or display wrong information.<br />
<br />
<br />
This issue affects Advant MOD 300 AdvaBuild: from 3.0 through 3.7 SP2.<br />
<br />
<br />
<br />
<br />
For an attack to be successful, the attacker must have local access to a node in the system and be able to<br />
start a specially crafted application that disrupts the communication.<br />
An attacker who successfully exploited the vulnerability would be able to manipulate the data in such<br />
way as allowing reads and writes to the controllers or cause Windows processes in 800xA for MOD 300<br />
and AdvaBuild to crash.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:abb:advabuild:*:*:*:*:*:advant_mod_300:*:* | 3.0 (including) | 3.7 (excluding) |
| cpe:2.3:a:abb:advabuild:3.7:-:*:*:*:advant_mod_300:*:* | ||
| cpe:2.3:a:abb:advabuild:3.7:sp1:*:*:*:advant_mod_300:*:* | ||
| cpe:2.3:a:abb:advabuild:3.7:sp2:*:*:*:advant_mod_300:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://search.abb.com/library/Download.aspx?DocumentID=3BUA003421&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.200044199.882581162.1721753430-284724496.1718609177
- https://search.abb.com/library/Download.aspx?DocumentID=3BUA003421&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.200044199.882581162.1721753430-284724496.1718609177



