PT-2020-15802 · Abb · Symphony Plus Historian+1

Published

2020-12-22

·

Updated

2021-09-14

·

CVE-2020-24676

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Symphony Plus Operations (affected versions not specified) Symphony Plus Historian (affected versions not specified)
Description The issue allows an unprivileged but authenticated user to execute arbitrary code, potentially resulting in privilege escalation. This depends on the user that the service runs as.
Recommendations For Symphony Plus Operations, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Symphony Plus Historian, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24676

Affected Products

Symphony Plus Historian
Symphony Plus -S+ Operations