Lucene search

K
cvelistABBCVELIST:CVE-2020-24678
HistoryDec 22, 2020 - 9:13 p.m.

CVE-2020-24678 Potential Privilege Escalation in Symphony Plus

2020-12-2221:13:13
CWE-269
ABB
www.cve.org
7
symphony plus
privilege escalation
authenticated user
malicious code
system control

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0.005

Percentile

77.7%

An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges.

CNA Affected

[
  {
    "product": "ABB Ability™ Symphony® Plus Operations",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "3.3 Service Pack 1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "2.1 SP2 Rollup 2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "lessThan": "2.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "ABB Ability™ Symphony® Plus Historian",
    "vendor": "ABB",
    "versions": [
      {
        "lessThan": "3.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0.005

Percentile

77.7%

Related for CVELIST:CVE-2020-24678