HIGH🇵🇱 Wersja polska

CVE-2020-24676

CVSS 7.8v3.1pub. 2020-12-22upd. 2024-11-21

In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Abb Symphony \+ Historian

    APP
    Abb
    3.03.1
  • Abb Symphony \+ Operations

    APP
    Abb
    1.12.02.13.03.13.23.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPE
CWE
References

Related vulnerabilities

CVE-2020-24673CRITICAL9.8PL ✓same product

SQL injection w ABB Symphony+ Operations i Symphony+ Historian

CVE-2020-24675CRITICAL9.8PL ✓same product

ABB Symphony+ — nieuwierzytelniony zapis wartości do procesu sterowania

CVE-2020-24683CRITICAL9.8PL ✓same product

ABB Symphony+ Operations — pominięcie uwierzytelnienia po stronie klienta

CVE-2020-24677HIGH8.8same product

Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution a...

CVE-2020-24678HIGH8.8same product

An authenticated user might execute malicious code under the user context and take control of the system. S+ O...