Unrated severityNVD Advisory· Published Dec 22, 2020· Updated Sep 16, 2024
Improper Authorization in Symphony Plus
CVE-2020-24674
Description
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
Affected products
2- ABB/ABB Ability™ Symphony® Plus Historianv5Range: unspecified
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- search.abb.com/library/Download.aspxmitrex_refsource_MISC
- search.abb.com/library/Download.aspxmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.