CVE-2020-24676: Insecure Windows Services in Symphony Plus
In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24676?
CVE-2020-24676 has a medium severity level due to its potential for privilege escalation.
How do I fix CVE-2020-24676?
To remediate CVE-2020-24676, update the affected versions of Symphony Plus Operations and Symphony Plus Historian to the latest patched versions.
What versions are affected by CVE-2020-24676?
CVE-2020-24676 affects Symphony Plus Operations versions 1.1, 2.0, 2.1 (SP1 and SP2), 3.0, 3.1, 3.2, and 3.3, as well as Symphony Plus Historian versions 3.0 and 3.1.
Who is affected by CVE-2020-24676?
Any organization using the specified versions of Symphony Plus Operations and Symphony Plus Historian is at risk of exploitation due to CVE-2020-24676.
What type of attack does CVE-2020-24676 facilitate?
CVE-2020-24676 enables unprivileged but authenticated users to execute arbitrary code, leading to privilege escalation.