cbcvebase.
CVE-2020-24676
published 2020-12-22

CVE-2020-24676: In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated)…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.2th percentile
In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.

Affected

13 ranges
VendorProductVersion rangeFixed in
abbabb_ability_symphony_plus_historian>= unspecified < 3.23.2
abbabb_ability_symphony_plus_operations>= unspecified < 3.3 Service Pack 13.3 Service Pack 1
abbabb_ability_symphony_plus_operations>= unspecified < 2.1 SP2 Rollup 22.1 SP2 Rollup 2
abbabb_ability_symphony_plus_operations>= unspecified < 2.22.2
abbsymphony_+_historian
abbsymphony_+_historian
abbsymphony_+_operations
abbsymphony_+_operations
abbsymphony_+_operations
abbsymphony_+_operations
abbsymphony_+_operations
abbsymphony_+_operations
abbsymphony_+_operations

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.