Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-24679— Denial of Service attack on Symphony Plus

CVSS 7.5 · High EPSS 0.76% · P74
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-24679

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Denial of Service attack on Symphony Plus
Source: NVD (National Vulnerability Database)
Vulnerability Description
A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
输入验证不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
ABB Symphony Plus Operations 和 ABB Symphony Plus Historian 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ABB Symphony Plus Operations和ABB Symphony Plus Historian都是瑞士ABB公司的产品。ABB Symphony Plus Operations是一个用于工业环境中为提高运营效率的管理设备。该设备提供易于使用的人机界面,无缝集成所有工厂设备和使用行业标准协议和技术的子系统,并提供警报管理、流程优化等功能。ABB Symphony Plus Historian是一个用于可视化查看管理工业设备历史信息的设备。 ABB Symphony Plus Operati
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
ABBABB Ability™ Symphony® Plus Operations unspecified ~ 3.3 Service Pack 1 -
ABBABB Ability™ Symphony® Plus Historian unspecified ~ 3.2 -

II. Public POCs for CVE-2020-24679

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-24679

登录查看更多情报信息。

Same Patch Batch · ABB · 2020-12-22 · 9 CVEs total

CVE-2020-246759.8 CRITICALWeak Authentication in Symphony Plus
CVE-2020-246739.8 CRITICALSQL Injection in Symphony Plus
CVE-2020-246839.8 CRITICALAuthentication Bypass in Symphony Plus
CVE-2020-246748.8 HIGHImproper Authorization in Symphony Plus
CVE-2020-246778.8 HIGHInsecure Web Service in Symphony Plus
CVE-2020-246788.8 HIGHPotential Privilege Escalation in Symphony Plus
CVE-2020-246767.8 HIGHInsecure Windows Services in Symphony Plus
CVE-2020-246807.0 HIGHImproper Credential Storage in Symphony Plus

IV. Related Vulnerabilities

V. Comments for CVE-2020-24679

No comments yet


Leave a comment