CVE-2020-24683: Authentication Bypass in Symphony Plus
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network communication or endpoints for these applications are not protected, unauthorized actors can bypass authentication and make unauthorized connections to the server application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24683?
The severity of CVE-2020-24683 is critical with a severity value of 9.8.
What software versions are affected by CVE-2020-24683?
The affected versions of software include Abb Symphony + Historian 3.0, Abb Symphony + Historian 3.1, Abb Symphony + Operations 1.1, Abb Symphony + Operations 2.0, Abb Symphony + Operations 2.1 SP1, Abb Symphony + Operations 2.1 SP2, Abb Symphony + Operations 3.0, Abb Symphony + Operations 3.1, Abb Symphony + Operations 3.2, and Abb Symphony + Operations 3.3.
What is the vulnerability description of CVE-2020-24683?
CVE-2020-24683 is a vulnerability in the user authentication approach of S+ Operations versions 2.1 SP1 and earlier, which relies on validation at the client node (client-side authentication) and is not as secure as server-side validation.
How can I fix CVE-2020-24683?
To fix CVE-2020-24683, it is recommended to update to a patched version or apply the relevant security updates provided by the software vendor.
Where can I find more information about CVE-2020-24683?
For more information about CVE-2020-24683, you can refer to the following reference: [link](https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch)