CVE Vulnerabilities

CVE-2020-24676

Improper Handling of Insufficient Privileges

Published: Dec 22, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.

Weakness

The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.

Affected Software

NameVendorStart VersionEnd Version
Symphony_+_historianAbb3.0 (including)3.0 (including)
Symphony_+_historianAbb3.1 (including)3.1 (including)
Symphony_+_operationsAbb1.1 (including)1.1 (including)
Symphony_+_operationsAbb2.0 (including)2.0 (including)
Symphony_+_operationsAbb2.1-sp1 (including)2.1-sp1 (including)
Symphony_+_operationsAbb2.1-sp2 (including)2.1-sp2 (including)
Symphony_+_operationsAbb3.0 (including)3.0 (including)
Symphony_+_operationsAbb3.1 (including)3.1 (including)
Symphony_+_operationsAbb3.2 (including)3.2 (including)
Symphony_+_operationsAbb3.3 (including)3.3 (including)

References