7.8

CVE-2020-24676

Insecure Windows Services in Symphony Plus

In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Abb ≫ Symphony + Historian Version 3.0
Abb ≫ Symphony + Historian Version 3.1
Abb ≫ Symphony + Operations Version 1.1
Abb ≫ Symphony + Operations Version 2.0
Abb ≫ Symphony + Operations Version 2.1 Update sp1
Abb ≫ Symphony + Operations Version 2.1 Update sp2
Abb ≫ Symphony + Operations Version 3.0
Abb ≫ Symphony + Operations Version 3.1
Abb ≫ Symphony + Operations Version 3.2
Abb ≫ Symphony + Operations Version 3.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.326
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
cybersecurity@ch.abb.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-274 Improper Handling of Insufficient Privileges

The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.

https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch
Vendor Advisory
Mitigation
https://search.abb.com/library/Download.aspx?DocumentID=2PAA123982&LanguageCode=en&DocumentPartId=&Action=Launch
Vendor Advisory
Mitigation