nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-24678 CVE-2020-24678
HIGH
Potential Privilege Escalation in Symphony Plus
Record summary
CVE-2020-24678 has a selected CVSS score of 8.8 (high).
Description
An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ABB Ability™ Symphony® Plus HistorianBrowse ABB / ABB Ability™ Symphony® Plus Historian | CVE List | Before 3.2 | affected |
ABB Ability™ Symphony® Plus OperationsBrowse ABB / ABB Ability™ Symphony® Plus Operations | CVE List | Before 3.3 Service Pack 1 | affected |
| Before 2.1 SP2 Rollup 2 | affected | ||
| Before 2.2 | affected |
References
3search.abb.com
https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch search.abb.com
https://search.abb.com/library/Download.aspx?DocumentID=2PAA123982&LanguageCode=en&DocumentPartId=&Action=Launch