CVE Vulnerabilities

CVE-2020-24676

Improper Handling of Insufficient Privileges

Published: Dec 22, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.

Weakness

The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Symphony_+_historian Abb 3.0 (including) 3.0 (including)
Symphony_+_historian Abb 3.1 (including) 3.1 (including)
Symphony_+_operations Abb 1.1 (including) 1.1 (including)
Symphony_+_operations Abb 2.0 (including) 2.0 (including)
Symphony_+_operations Abb 2.1-sp1 (including) 2.1-sp1 (including)
Symphony_+_operations Abb 2.1-sp2 (including) 2.1-sp2 (including)
Symphony_+_operations Abb 3.0 (including) 3.0 (including)
Symphony_+_operations Abb 3.1 (including) 3.1 (including)
Symphony_+_operations Abb 3.2 (including) 3.2 (including)
Symphony_+_operations Abb 3.3 (including) 3.3 (including)

References