In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-17388 In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 16 Sep 2024 17:00:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Symphony Plus Improper Authorization in Symphony Plus

cve-icon MITRE

Status: PUBLISHED

Assigner: ABB

Published:

Updated: 2024-09-16T16:54:08.113Z

Reserved: 2020-08-26T00:00:00

Link: CVE-2020-24674

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-22T22:15:13.147

Modified: 2024-11-21T05:15:41.573

Link: CVE-2020-24674

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.