Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-24674— Improper Authorization in Symphony Plus

CVSS 8.8 · High EPSS 4.18% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-24674

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper Authorization in Symphony Plus
Source: NVD (National Vulnerability Database)
Vulnerability Description
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
ABB Symphony Plus Operations 和 ABB Symphony Plus Historian 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ABB Symphony Plus Operations和ABB Symphony Plus Historian都是瑞士ABB公司的产品。ABB Symphony Plus Operations是一个用于工业环境中为提高运营效率的管理设备。该设备提供易于使用的人机界面,无缝集成所有工厂设备和使用行业标准协议和技术的子系统,并提供警报管理、流程优化等功能。ABB Symphony Plus Historian是一个用于可视化查看管理工业设备历史信息的设备。 ABB Symphony Plus Operati
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
ABBABB Ability™ Symphony® Plus Operations unspecified ~ 3.3 Service Pack 1 -
ABBABB Ability™ Symphony® Plus Historian unspecified ~ 3.2 -

II. Public POCs for CVE-2020-24674

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-24674

登录查看更多情报信息。

Same Patch Batch · ABB · 2020-12-22 · 9 CVEs total

CVE-2020-246759.8 CRITICALWeak Authentication in Symphony Plus
CVE-2020-246739.8 CRITICALSQL Injection in Symphony Plus
CVE-2020-246839.8 CRITICALAuthentication Bypass in Symphony Plus
CVE-2020-246778.8 HIGHInsecure Web Service in Symphony Plus
CVE-2020-246788.8 HIGHPotential Privilege Escalation in Symphony Plus
CVE-2020-246767.8 HIGHInsecure Windows Services in Symphony Plus
CVE-2020-246797.5 HIGHDenial of Service attack on Symphony Plus
CVE-2020-246807.0 HIGHImproper Credential Storage in Symphony Plus

IV. Related Vulnerabilities

V. Comments for CVE-2020-24674

No comments yet


Leave a comment