In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAbb Symphony \+ Historian
APPAbb3.03.1Abb Symphony \+ Operations
APPAbb1.12.02.13.03.13.23.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCELPE
Powiązane podatności
CVE-2020-24673CRITICAL9.8PL ✓ten sam produkt
SQL injection w ABB Symphony+ Operations i Symphony+ Historian
CVE-2020-24675CRITICAL9.8PL ✓ten sam produkt
ABB Symphony+ — nieuwierzytelniony zapis wartości do procesu sterowania
CVE-2020-24683CRITICAL9.8PL ✓ten sam produkt
ABB Symphony+ Operations — pominięcie uwierzytelnienia po stronie klienta
CVE-2020-24677HIGH8.8ten sam produkt
Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution a...
CVE-2020-24678HIGH8.8ten sam produkt
An authenticated user might execute malicious code under the user context and take control of the system. S+ O...