8.8

CVE-2020-24677

Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data.

Data is provided by the National Vulnerability Database (NVD)
AbbSymphony + Historian Version3.0
AbbSymphony + Historian Version3.1
AbbSymphony + Operations Version1.1
AbbSymphony + Operations Version2.0
AbbSymphony + Operations Version2.1 Updatesp1
AbbSymphony + Operations Version2.1 Updatesp2
AbbSymphony + Operations Version3.0
AbbSymphony + Operations Version3.1
AbbSymphony + Operations Version3.2
AbbSymphony + Operations Version3.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.14% 0.764
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
cybersecurity@ch.abb.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-754 Improper Check for Unusual or Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.