8.8

CVE-2023-0228

Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.

Data is provided by the National Vulnerability Database (NVD)
AbbSymphony Plus S+ Operations Version >= 2.0 < 2.1
AbbSymphony Plus S+ Operations Version >= 3.0 < 3.3
AbbSymphony Plus S+ Operations Version2.1 Update-
AbbSymphony Plus S+ Operations Version2.1 Updatesp2
AbbSymphony Plus S+ Operations Version3.3 Update-
AbbSymphony Plus S+ Operations Version3.3 Updatesp1
AbbSymphony Plus S+ Operations Version3.3 Updatesp2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.264
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cybersecurity@ch.abb.com 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.