Vulnerability Details CVE-2020-24674
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.048
EPSS Ranking 89.0%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.0
Products affected by CVE-2020-24674
-
cpe:2.3:a:abb:symphony_+_historian:3.0
-
cpe:2.3:a:abb:symphony_+_historian:3.1
-
cpe:2.3:a:abb:symphony_+_operations:1.1
-
cpe:2.3:a:abb:symphony_+_operations:2.0
-
cpe:2.3:a:abb:symphony_+_operations:2.1
-
cpe:2.3:a:abb:symphony_+_operations:3.0
-
cpe:2.3:a:abb:symphony_+_operations:3.1
-
cpe:2.3:a:abb:symphony_+_operations:3.2
-
cpe:2.3:a:abb:symphony_+_operations:3.3