In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAbb Symphony \+ Historian
APPAbb3.03.1Abb Symphony \+ Operations
APPAbb1.12.02.13.03.13.23.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPE
Related vulnerabilities
CVE-2020-24673CRITICAL9.8PL ✓same product
SQL injection w ABB Symphony+ Operations i Symphony+ Historian
CVE-2020-24675CRITICAL9.8PL ✓same product
ABB Symphony+ — nieuwierzytelniony zapis wartości do procesu sterowania
CVE-2020-24683CRITICAL9.8PL ✓same product
ABB Symphony+ Operations — pominięcie uwierzytelnienia po stronie klienta
CVE-2020-24677HIGH8.8same product
Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution a...
CVE-2020-24678HIGH8.8same product
An authenticated user might execute malicious code under the user context and take control of the system. S+ O...