A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HAbb Symphony \+ Historian
APPAbb3.03.1Abb Symphony \+ Operations
APPAbb1.12.02.13.03.13.23.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
Powiązane podatności
CVE-2020-24673CRITICAL9.8PL ✓ten sam produkt
SQL injection w ABB Symphony+ Operations i Symphony+ Historian
CVE-2020-24675CRITICAL9.8PL ✓ten sam produkt
ABB Symphony+ — nieuwierzytelniony zapis wartości do procesu sterowania
CVE-2020-24683CRITICAL9.8PL ✓ten sam produkt
ABB Symphony+ Operations — pominięcie uwierzytelnienia po stronie klienta
CVE-2020-24676HIGH7.8ten sam produkt
In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalati...
CVE-2020-24677HIGH8.8ten sam produkt
Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution a...