CVE-2020-11640
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
23/07/2024
Last modified:
19/12/2025
Description
AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the<br />
command queue can use it to launch an attack by running any executable on the AdvaBuild node. The<br />
executables that can be run are not limited to AdvaBuild specific executables. <br />
<br />
Improper Privilege Management vulnerability in ABB Advant MOD 300 AdvaBuild.This issue affects Advant MOD 300 AdvaBuild: from 3.0 through 3.7 SP2.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:abb:advabuild:*:*:*:*:*:advant_mod_300:*:* | 3.0 (including) | 3.7 (excluding) |
| cpe:2.3:a:abb:advabuild:3.7:-:*:*:*:advant_mod_300:*:* | ||
| cpe:2.3:a:abb:advabuild:3.7:sp1:*:*:*:advant_mod_300:*:* | ||
| cpe:2.3:a:abb:advabuild:3.7:sp2:*:*:*:advant_mod_300:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://search.abb.com/library/Download.aspx?DocumentID=3BUA003421&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.200044199.882581162.1721753430-284724496.1718609177
- https://search.abb.com/library/Download.aspx?DocumentID=3BUA003421&LanguageCode=en&DocumentPartId=&Action=Launch&_ga=2.200044199.882581162.1721753430-284724496.1718609177



