CVE Published: 22/12/2020 |
CVE Updated: 16/09/2024 |
CVE Year: 2020 Source: ABB |
Vendor: ABB |
Product: ABB Ability™ Symphony® Plus Operations Status : PUBLISHED
CVE-2020-24676 Description
In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.
Metrics
CVSS Version: 3.1 |
Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H