CVE-2020-24676
Summary
| CVE | CVE-2020-24676 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-22 22:15:00 UTC |
| Updated | 2021-09-14 15:23:00 UTC |
| Description | In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Abb | Symphony Historian | 3.0 | All | All | All |
| Application | Abb | Symphony Historian | 3.1 | All | All | All |
| Application | Abb | Symphony Historian | 3.0 | All | All | All |
| Application | Abb | Symphony Historian | 3.1 | All | All | All |
| Application | Abb | Symphony Operations | 1.1 | All | All | All |
| Application | Abb | Symphony Operations | 2.0 | All | All | All |
| Application | Abb | Symphony Operations | 2.1 | sp1 | All | All |
| Application | Abb | Symphony Operations | 2.1 | sp2 | All | All |
| Application | Abb | Symphony Operations | 3.0 | All | All | All |
| Application | Abb | Symphony Operations | 3.1 | All | All | All |
| Application | Abb | Symphony Operations | 3.2 | All | All | All |
| Application | Abb | Symphony Operations | 3.3 | All | All | All |
| Application | Abb | Symphony Operations | 1.1 | All | All | All |
| Application | Abb | Symphony Operations | 2.0 | All | All | All |
| Application | Abb | Symphony Operations | 2.1 | sp1 | All | All |
| Application | Abb | Symphony Operations | 2.1 | sp2 | All | All |
| Application | Abb | Symphony Operations | 3.0 | All | All | All |
| Application | Abb | Symphony Operations | 3.1 | All | All | All |
| Application | Abb | Symphony Operations | 3.2 | All | All | All |
| Application | Abb | Symphony Operations | 3.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SECURITY Multiple Vulnerabilities in S+ Historian | MISC | search.abb.com | Mitigation, Vendor Advisory |
| search.abb.com/library/Download.aspx | MISC | search.abb.com | Mitigation, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.