An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAbb Symphony \+ Historian
APPAbb3.03.1Abb Symphony \+ Operations
APPAbb1.12.02.13.03.13.23.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2020-24673CRITICAL9.8PL ✓same product
SQL injection w ABB Symphony+ Operations i Symphony+ Historian
CVE-2020-24675CRITICAL9.8PL ✓same product
ABB Symphony+ — nieuwierzytelniony zapis wartości do procesu sterowania
CVE-2020-24683CRITICAL9.8PL ✓same product
ABB Symphony+ Operations — pominięcie uwierzytelnienia po stronie klienta
CVE-2020-24676HIGH7.8same product
In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalati...
CVE-2020-24677HIGH8.8same product
Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution a...