7.8
CVSSv3

CVE-2020-24676

Published: 22/12/2020 Updated: 14/09/2021
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

abb symphony \\+ historian 3.0

abb symphony \\+ historian 3.1

abb symphony \\+ operations 1.1

abb symphony \\+ operations 2.0

abb symphony \\+ operations 2.1

abb symphony \\+ operations 3.0

abb symphony \\+ operations 3.1

abb symphony \\+ operations 3.2

abb symphony \\+ operations 3.3