CVE-2020-11640

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
23/07/2024
Last modified:
19/12/2025

Description

AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the<br /> command queue can use it to launch an attack by running any executable on the AdvaBuild node. The<br /> executables that can be run are not limited to AdvaBuild specific executables. <br /> <br /> Improper Privilege Management vulnerability in ABB Advant MOD 300 AdvaBuild.This issue affects Advant MOD 300 AdvaBuild: from 3.0 through 3.7 SP2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:abb:advabuild:*:*:*:*:*:advant_mod_300:*:* 3.0 (including) 3.7 (excluding)
cpe:2.3:a:abb:advabuild:3.7:-:*:*:*:advant_mod_300:*:*
cpe:2.3:a:abb:advabuild:3.7:sp1:*:*:*:advant_mod_300:*:*
cpe:2.3:a:abb:advabuild:3.7:sp2:*:*:*:advant_mod_300:*:*