CVE-2020-24679

CRITICAL WAF: Medium
CVSS 9.8 Published: 2020-12-22
CWE-20 CWE-20

A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.

WAF Coverage Analysis

Improper Input Validation Medium WAF Coverage

OWASP: A03:2021 Injection

920xxx - Protocol Enforcement 941xxx - XSS / XXE 942xxx - SQL Injection
Improper Input Validation Medium WAF Coverage

OWASP: A03:2021 Injection

920xxx - Protocol Enforcement 941xxx - XSS / XXE 942xxx - SQL Injection

Affected Software

VendorProductVersion
abbsymphony_\+_historian3.0
abbsymphony_\+_historian3.1
abbsymphony_\+_operations1.1
abbsymphony_\+_operations2.0
abbsymphony_\+_operations2.1
abbsymphony_\+_operations2.1
abbsymphony_\+_operations3.0
abbsymphony_\+_operations3.1
abbsymphony_\+_operations3.2
abbsymphony_\+_operations3.3

References

Back to CVE Database