ABB Central Licensing System - Information disclosure
Published Apr 29, 2020
9.8
CRITICALCVSS 3.1
EPSS 1.85%
Description
For ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony 5.1, 6.0 and 6.1, Melody Composer 5.3, 6.1/6.2 and SPE for Melody 1.0SPx (Composer 6.3), Harmony OPC Server (HAOPC) Standalone 6.0, 6.1 and 7.0, ABB Ability™ System 800xA/ Advant® OCS Control Builder A 1.3 and 1.4, Advant® OCS AC100 OPC Server 5.1, 6.0 and 6.1, Composer CTK 6.1 and 6.2, AdvaBuild 3.7 SP1 and SP2, OPCServer for MOD 300 (non-800xA) 1.4, OPC Data Link 2.1 and 2.2, Knowledge Manager 8.0, 9.0 and 9.1, Manufacturing Operations Management 1812 and 1909, confidential data is written in an unprotected file. An attacker who successfully exploited this vulnerability could take full control of the computer.
Affected products
-
- Version 5.1StatusaffectedConstraints-
- Version 6.0StatusaffectedConstraints-
- Version 6.1StatusaffectedConstraints-
- Version
-
- Version 3.7 SP1StatusaffectedConstraints-
- Version 3.7 SP2StatusaffectedConstraints-
- Version
-
- Version 5.1StatusaffectedConstraints-
- Version 6.0StatusaffectedConstraints-
- Version 6.1StatusaffectedConstraints-
- Version
-
- Version 1.3StatusaffectedConstraints-
- Version 1.4StatusaffectedConstraints-
- Version
-
- Version 5.1StatusaffectedConstraints<5*
- Version
-
- Version 5.1StatusaffectedConstraints-
- Version 6.0StatusaffectedConstraints-
- Version
-
- Version 6.1StatusaffectedConstraints-
- Version 6.2StatusaffectedConstraints-
- Version
-
- Version 5.1StatusaffectedConstraints-
- Version 6.0StatusaffectedConstraints-
- Version 6.1StatusaffectedConstraints-
- Version
-
- Version 5.3StatusaffectedConstraints-
- Version 6StatusaffectedConstraints<=6.3
- Version
-
- Version 1.0StatusaffectedConstraints-
- Version 1.1StatusaffectedConstraints-
- Version 2.0StatusaffectedConstraints-
- Version
-
- Version 6.0StatusaffectedConstraints-
- Version 6.1StatusaffectedConstraints-
- Version 7.0StatusaffectedConstraints-
- Version
-
- Version 8.0StatusaffectedConstraints-
- Version 9.0StatusaffectedConstraints-
- Version 9.1StatusaffectedConstraints-
- Version
-
- Version 1812StatusaffectedConstraints-
- Version 1909StatusaffectedConstraints-
- Version
-
- Version 2.1StatusaffectedConstraints-
- Version 2.2StatusaffectedConstraints-
- Version
-
- Version 1.4StatusaffectedConstraints-
- Version
-
- Version 1.1StatusaffectedConstraints<=2.2
- Version
-
- Version 3StatusaffectedConstraints<=3.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ABB | ABB Ability System 800xA | n/a |
| ||||||||||||
| ABB | AdvaBuild | n/a |
| ||||||||||||
| ABB | Advant OCS AC 100 OPS Server | n/a |
| ||||||||||||
| ABB | Advant OCS Control Builder A | n/a |
| ||||||||||||
| ABB | Central Licensing System | n/a |
| ||||||||||||
| ABB | Compact HMI | n/a |
| ||||||||||||
| ABB | Composer CTK | n/a |
| ||||||||||||
| ABB | Composer Harmony | n/a |
| ||||||||||||
| ABB | Composer Melody | n/a |
| ||||||||||||
| ABB | Control Builder Safe | n/a |
| ||||||||||||
| ABB | Harmony OPC Server Standalone | n/a |
| ||||||||||||
| ABB | Knowledge Manager | n/a |
| ||||||||||||
| ABB | Manufacturing Operations Management | n/a |
| ||||||||||||
| ABB | OPC Data Link | n/a |
| ||||||||||||
| ABB | OPC Server for Mod 300 (non-800xA) | n/a |
| ||||||||||||
| ABB | Symphony Plus S+ Engineering | n/a |
| ||||||||||||
| ABB | Symphony Plus S+ Operations | n/a |
|
- 5.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.85% (0.01855) | 78.43th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.81% (0.01810) | 75.71th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.24% (0.00244) | 64.91th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.24% (0.00244) | 63.53th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00244) | 60.55th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.03% (0.09029) | 86.86th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.74% (0.02742) | 63.06th | v5 (v2026.06.15) |
| Jan 6, 2022 | 2.74% (0.02742) | 62.72th | v1 |
| Sep 1, 2021 | 0.62% (0.00624) | 45.04th | v1 |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (2)
- https://search.abb.com/library/Download.aspx?DocumentID=2PAA121230&LanguageCode=en&DocumentPartId=&Action=Launch x_refsource_CONFIRMVendor Advisory
- https://search.abb.com/library/Download.aspx?DocumentID=2PAA121231&LanguageCode=en&DocumentPartId=&Action=Launch x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://search.abb.com/library/Download.aspx?DocumentID=2PAA121230&LanguageCode=en&DocumentPartId=&Action=Launch | x_refsource_CONFIRMVendor Advisory | |
| https://search.abb.com/library/Download.aspx?DocumentID=2PAA121231&LanguageCode=en&DocumentPartId=&Action=Launch | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.