← back
CVE-2020-24674highCWE-285

Improper Authorization in Symphony Plus

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 3.1%
exploitation probability
3.1%top 13% of all CVEs
observed exploitation
nono source reports it
In short

Symphony Plus has a flaw where some commands don't properly check if users are allowed to run them. This means an authenticated user could perform actions they shouldn't have access to, like crashing the system or running malicious code.

Technical detail

CWE-285 improper authorization vulnerability in S+ Operations and S+ Historian allows authenticated but insufficiently-privileged users to bypass permission checks on certain client commands, enabling DoS attacks, arbitrary code execution, or privilege escalation via unvalidated command execution.

Summary generated and translated by AI from the official description.
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H