Potential Privilege Escalation in Symphony Plus
CVE-2020-24678
8.8HIGH
What is CVE-2020-24678?
An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges.
Affected Version(s)
ABB Ability™ Symphony® Plus Historian < 3.2
ABB Ability™ Symphony® Plus Operations < 3.3 Service Pack 1
ABB Ability™ Symphony® Plus Operations < 2.1 SP2 Rollup 2