Lucene search

K
cveABBCVE-2020-24679
HistoryDec 22, 2020 - 10:15 p.m.

CVE-2020-24679

2020-12-2222:15:13
CWE-20
ABB
web.nvd.nist.gov
42
1
cve-2020-24679
s+ operations
s+ historian
dos
code execution
vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.008

Percentile

81.8%

A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.

Affected configurations

Nvd
Node
abbsymphony_\+_historianMatch3.0
OR
abbsymphony_\+_historianMatch3.1
OR
abbsymphony_\+_operationsMatch1.1
OR
abbsymphony_\+_operationsMatch2.0
OR
abbsymphony_\+_operationsMatch2.1sp1
OR
abbsymphony_\+_operationsMatch2.1sp2
OR
abbsymphony_\+_operationsMatch3.0
OR
abbsymphony_\+_operationsMatch3.1
OR
abbsymphony_\+_operationsMatch3.2
OR
abbsymphony_\+_operationsMatch3.3
VendorProductVersionCPE
abbsymphony_\+_historian3.0cpe:2.3:a:abb:symphony_\+_historian:3.0:*:*:*:*:*:*:*
abbsymphony_\+_historian3.1cpe:2.3:a:abb:symphony_\+_historian:3.1:*:*:*:*:*:*:*
abbsymphony_\+_operations1.1cpe:2.3:a:abb:symphony_\+_operations:1.1:*:*:*:*:*:*:*
abbsymphony_\+_operations2.0cpe:2.3:a:abb:symphony_\+_operations:2.0:*:*:*:*:*:*:*
abbsymphony_\+_operations2.1cpe:2.3:a:abb:symphony_\+_operations:2.1:sp1:*:*:*:*:*:*
abbsymphony_\+_operations2.1cpe:2.3:a:abb:symphony_\+_operations:2.1:sp2:*:*:*:*:*:*
abbsymphony_\+_operations3.0cpe:2.3:a:abb:symphony_\+_operations:3.0:*:*:*:*:*:*:*
abbsymphony_\+_operations3.1cpe:2.3:a:abb:symphony_\+_operations:3.1:*:*:*:*:*:*:*
abbsymphony_\+_operations3.2cpe:2.3:a:abb:symphony_\+_operations:3.2:*:*:*:*:*:*:*
abbsymphony_\+_operations3.3cpe:2.3:a:abb:symphony_\+_operations:3.3:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "ABB Ability™ Symphony® Plus Operations",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "3.3 Service Pack 1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "2.1 SP2 Rollup 2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "2.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "ABB Ability™ Symphony® Plus Historian",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "3.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.5

Confidence

High

EPSS

0.008

Percentile

81.8%

Related for CVE-2020-24679