CRITICAL🇵🇱 Wersja polska

CVE-2020-24683

CVSS 9.8v3.1pub. 2020-12-22upd. 2024-11-21

The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network communication or endpoints for these applications are not protected, unauthorized actors can bypass authentication and make unauthorized connections to the server application.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Abb Symphony \+ Historian

    APP
    Abb
    3.03.1
  • Abb Symphony \+ Operations

    APP
    Abb
    1.12.02.13.03.13.23.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2020-24675CRITICAL9.8PL ✓same product

ABB Symphony+ — nieuwierzytelniony zapis wartości do procesu sterowania

CVE-2020-24673CRITICAL9.8PL ✓same product

SQL injection w ABB Symphony+ Operations i Symphony+ Historian

CVE-2020-24676HIGH7.8same product

In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalati...

CVE-2020-24677HIGH8.8same product

Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution a...

CVE-2020-24678HIGH8.8same product

An authenticated user might execute malicious code under the user context and take control of the system. S+ O...