CVE detail
CVE-2020-24674 — CVE-2020-24674
Published 2020-12-22 · Modified 2026-06-17 · Vendor abb · Product symphony_\+_historian · Source nvd
HIGH
severity
CVSS-derived band
0.0298
EPSS probability
exploitation probability, 30d
86.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References