CVE-2020-24678: Potential Privilege Escalation in Symphony Plus
An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-24678?
CVE-2020-24678 is a vulnerability that allows an authenticated user to execute malicious code and gain control of the system.
Which software is affected by CVE-2020-24678?
Abb Symphony + Historian versions 3.0 and 3.1, and Abb Symphony + Operations versions 1.1, 2.0, 2.1-sp1, 2.1-sp2, 3.0, 3.1, 3.2, and 3.3 are affected by CVE-2020-24678.
What is the severity of CVE-2020-24678?
CVE-2020-24678 has a severity rating of 8.8 (High).
How can an authenticated user exploit CVE-2020-24678?
An authenticated user can exploit CVE-2020-24678 by executing malicious code under the user context, gaining control of the system.
Where can I find more information about CVE-2020-24678?
You can find more information about CVE-2020-24678 [here](https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch) and [here](https://search.abb.com/library/Download.aspx?DocumentID=2PAA123982&LanguageCode=en&DocumentPartId=&Action=Launch).