In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAbb Symphony \+ Historian
APPAbb3.03.1Abb Symphony \+ Operations
APPAbb1.12.02.13.03.13.23.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2020-24673CRITICAL9.8PL ✓same product
SQL injection w ABB Symphony+ Operations i Symphony+ Historian
CVE-2020-24675CRITICAL9.8PL ✓same product
ABB Symphony+ — nieuwierzytelniony zapis wartości do procesu sterowania
CVE-2020-24683CRITICAL9.8PL ✓same product
ABB Symphony+ Operations — pominięcie uwierzytelnienia po stronie klienta
CVE-2020-24677HIGH8.8same product
Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution a...
CVE-2020-24678HIGH8.8same product
An authenticated user might execute malicious code under the user context and take control of the system. S+ O...