SB2020060316 - Multiple vulnerabilities in ABB Central Licensing System 



SB2020060316 - Multiple vulnerabilities in ABB Central Licensing System

Published: June 3, 2020

Security Bulletin ID SB2020060316
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) XML External Entity injection (CVE-ID: CVE-2020-8479)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or block license handling.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.

This vulnerability affects the following ABB CLS products:

  • ABB Ability System 800xA and related system extensions: Versions 5.1, 6.0, 6.1
  • Compact HMI: Versions 5.1, 6.0
  • Control Builder Safe: Versions 1.0, 1.1, 2.0
  • ABB Ability Symphony Plus – S+ Operations: Versions 3.0 to 3.2
  • ABB Ability Symphony Plus – S+ Engineering: Versions 1.1 to 2.2
  • Composer Harmony: Versions 5.1, 6.0, 6.1
  • Composer Melody (incl. SPE for Melody 1.0 SPx): Versions 5.3, 6.1, 6.2, 6.3
  • Harmony OPC Server (HAOPC): Standalone Versions 6.0, 6.1, 7.0
  • ABB Ability System 800xA / Advant OCS Control Builder A: Versions 1.3, 1.4
  • Advant OCS AC 100 OPC Server: Versions 5.1, 6.0, 6.1
  • Composer CTK: Versions 6.1, 6.2
  • AdvaBuild: Versions 3.7 SP1, 3.7 SP2
  • OPC Server MOD 300 (non-800xA): Version 1.4
  • OPC Data Link: Versions 2.1, 2.2
  • ABB Ability Knowledge Manager: Versions 8.0, 9.0, 9.1
  • ABB Ability Manufacturing Operations Management: Versions 1812, 1909

2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2020-8471)

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to weak file permissions. A local user can modify the system-wide configuration and gain elevated privileges on the target system, or generate denialof-service effects through file deletion or modification.

This vulnerability affects the following ABB CLS products:

  • ABB Ability System 800xA and related system extensions: Versions 5.1, 6.0, 6.1
  • Compact HMI: Versions 5.1, 6.0
  • Control Builder Safe: Versions 1.0, 1.1, 2.0
  • ABB Ability Symphony Plus – S+ Operations: Versions 3.0 to 3.2
  • ABB Ability Symphony Plus – S+ Engineering: Versions 1.1 to 2.2
  • Composer Harmony: Versions 5.1, 6.0, 6.1
  • Composer Melody (incl. SPE for Melody 1.0 SPx): Versions 5.3, 6.1, 6.2, 6.3
  • Harmony OPC Server (HAOPC): Standalone Versions 6.0, 6.1, 7.0
  • ABB Ability System 800xA / Advant OCS Control Builder A: Versions 1.3, 1.4
  • Advant OCS AC 100 OPC Server: Versions 5.1, 6.0, 6.1
  • Composer CTK: Versions 6.1, 6.2
  • AdvaBuild: Versions 3.7 SP1, 3.7 SP2
  • OPC Server MOD 300 (non-800xA): Version 1.4
  • OPC Data Link: Versions 2.1, 2.2
  • ABB Ability Knowledge Manager: Versions 8.0, 9.0, 9.1
  • ABB Ability Manufacturing Operations Management: Versions 1812, 1909

Remediation

Install update from vendor's website.