CVE-2020-24675

CRITICAL WAF: Low
CVSS 9.8 Published: 2020-12-22
CWE-287 CWE-287

In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process.

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
abbsymphony_\+_historian3.0
abbsymphony_\+_historian3.1
abbsymphony_\+_operations1.1
abbsymphony_\+_operations2.0
abbsymphony_\+_operations2.1
abbsymphony_\+_operations2.1
abbsymphony_\+_operations3.0
abbsymphony_\+_operations3.1
abbsymphony_\+_operations3.2
abbsymphony_\+_operations3.3

References

Back to CVE Database