Denial of Service attack on Symphony Plus
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 1.9%
exploitation probability
1.9%top 22% of all CVEs
observed exploitation
nono source reports it
In short
Symphony Plus services can be crashed or compromised by sending specially crafted messages over the network. This allows attackers to disrupt operations or potentially take control of the affected system.
Technical detail
CWE-20 input validation flaw in S+ Operations and S+ Historian services allows remote attackers to trigger denial of service or arbitrary code execution via malformed messages without requiring authentication or special privileges.
Summary generated and translated by AI from the official description.
A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H