« Volver al listado

CVE-2020-24677

Estado: ModificadaAlta (8.8)—

Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-24677",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cybersecurity@ch.abb.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@ch.abb.com",
      "affectedData": [
        {
          "vendor": "ABB",
          "product": "ABB Ability™ Symphony® Plus Operations",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.3 Service Pack 1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.1 SP2 Rollup 2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.2",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "ABB",
          "product": "ABB Ability™ Symphony® Plus Historian",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "3.2",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-22T22:15:13.413",
  "references": [
    {
      "url": "https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "cybersecurity@ch.abb.com"
    },
    {
      "url": "https://search.abb.com/library/Download.aspx?DocumentID=2PAA123982&LanguageCode=en&DocumentPartId=&Action=Launch",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "cybersecurity@ch.abb.com"
    },
    {
      "url": "https://search.abb.com/library/Download.aspx?DocumentID=2PAA123980&LanguageCode=en&DocumentPartId=&Action=Launch",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://search.abb.com/library/Download.aspx?DocumentID=2PAA123982&LanguageCode=en&DocumentPartId=&Action=Launch",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@ch.abb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-754"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-754"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data."
    },
    {
      "lang": "es",
      "value": "Las vulnerabilidades en las aplicaciones web S+ Operations y S+ Historian, pueden conducir a una posible ejecución de código y escalada de privilegios, un redireccionamiento del usuario a otro lugar o una descarga de datos no deseados"
    }
  ],
  "lastModified": "2026-06-17T03:05:58.073",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:abb:symphony_\\+_historian:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAAEE275-0C2C-4D15-B0CB-B51706015769"
            },
            {
              "criteria": "cpe:2.3:a:abb:symphony_\\+_historian:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A89B5F4-5BE7-4B0E-9ADF-46630017221C"
            },
            {
              "criteria": "cpe:2.3:a:abb:symphony_\\+_operations:1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "21FB4D84-598C-486D-9A16-F24AEAA8B2A5"
            },
            {
              "criteria": "cpe:2.3:a:abb:symphony_\\+_operations:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96371CD8-6C8A-459E-9A7E-34694B9F648E"
            },
            {
              "criteria": "cpe:2.3:a:abb:symphony_\\+_operations:2.1:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D3E3D88-6544-459D-A5F3-AFB682FF8462"
            },
            {
              "criteria": "cpe:2.3:a:abb:symphony_\\+_operations:2.1:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED64EBDB-B30B-49ED-88C9-7FC2B092FEA3"
            },
            {
              "criteria": "cpe:2.3:a:abb:symphony_\\+_operations:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6281EC9-5771-4B95-B18C-C11A0EABDA25"
            },
            {
              "criteria": "cpe:2.3:a:abb:symphony_\\+_operations:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B553708-205B-4B87-BFE9-1570C1AAE06F"
            },
            {
              "criteria": "cpe:2.3:a:abb:symphony_\\+_operations:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C8D38257-9207-4AED-818F-EA6E09393491"
            },
            {
              "criteria": "cpe:2.3:a:abb:symphony_\\+_operations:3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7EBFA7A6-0EF8-46FC-B92F-AF448531B997"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cybersecurity@ch.abb.com"
}