HIGH🇬🇧 English

CVE-2020-24679

CVSS 7.5v3.1pub. 2020-12-22upd. 2024-11-21

A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Abb Symphony \+ Historian

    APP
    Abb
    3.03.1
  • Abb Symphony \+ Operations

    APP
    Abb
    1.12.02.13.03.13.23.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Referencje

Powiązane podatności

CVE-2020-24673CRITICAL9.8PL ✓ten sam produkt

SQL injection w ABB Symphony+ Operations i Symphony+ Historian

CVE-2020-24675CRITICAL9.8PL ✓ten sam produkt

ABB Symphony+ — nieuwierzytelniony zapis wartości do procesu sterowania

CVE-2020-24683CRITICAL9.8PL ✓ten sam produkt

ABB Symphony+ Operations — pominięcie uwierzytelnienia po stronie klienta

CVE-2020-24676HIGH7.8ten sam produkt

In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalati...

CVE-2020-24677HIGH8.8ten sam produkt

Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution a...