Lucene search

K
nvd[email protected]NVD:CVE-2020-24679
HistoryDec 22, 2020 - 10:15 p.m.

CVE-2020-24679

2020-12-2222:15:13
CWE-20
web.nvd.nist.gov
3
vulnerability
s+ operations
historian
dos
code execution

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.008

Percentile

81.8%

A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.

Affected configurations

Nvd
Node
abbsymphony_\+_historianMatch3.0
OR
abbsymphony_\+_historianMatch3.1
OR
abbsymphony_\+_operationsMatch1.1
OR
abbsymphony_\+_operationsMatch2.0
OR
abbsymphony_\+_operationsMatch2.1sp1
OR
abbsymphony_\+_operationsMatch2.1sp2
OR
abbsymphony_\+_operationsMatch3.0
OR
abbsymphony_\+_operationsMatch3.1
OR
abbsymphony_\+_operationsMatch3.2
OR
abbsymphony_\+_operationsMatch3.3
VendorProductVersionCPE
abbsymphony_\+_historian3.0cpe:2.3:a:abb:symphony_\+_historian:3.0:*:*:*:*:*:*:*
abbsymphony_\+_historian3.1cpe:2.3:a:abb:symphony_\+_historian:3.1:*:*:*:*:*:*:*
abbsymphony_\+_operations1.1cpe:2.3:a:abb:symphony_\+_operations:1.1:*:*:*:*:*:*:*
abbsymphony_\+_operations2.0cpe:2.3:a:abb:symphony_\+_operations:2.0:*:*:*:*:*:*:*
abbsymphony_\+_operations2.1cpe:2.3:a:abb:symphony_\+_operations:2.1:sp1:*:*:*:*:*:*
abbsymphony_\+_operations2.1cpe:2.3:a:abb:symphony_\+_operations:2.1:sp2:*:*:*:*:*:*
abbsymphony_\+_operations3.0cpe:2.3:a:abb:symphony_\+_operations:3.0:*:*:*:*:*:*:*
abbsymphony_\+_operations3.1cpe:2.3:a:abb:symphony_\+_operations:3.1:*:*:*:*:*:*:*
abbsymphony_\+_operations3.2cpe:2.3:a:abb:symphony_\+_operations:3.2:*:*:*:*:*:*:*
abbsymphony_\+_operations3.3cpe:2.3:a:abb:symphony_\+_operations:3.3:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.008

Percentile

81.8%

Related for NVD:CVE-2020-24679