Back to Database
Status published
High
CVE-2020-24674
Improper Authorization in Symphony Plus
Vulnerability Description
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-24674
Credits & Attribution
No credits recorded in the NVD database.
References
More from ABB
View All →CVE-2025-9970
Application credential stored in clear text in memory
Medium
5.7
CVE-2025-9574
Missing Authentication Vulnerability
Critical
9.9
CVE-2025-8754
ABB AbilityTM zenon Remote Transport Vulnerability
High
8.7
CVE-2025-7745
Modbus TCP buffer overread
Medium
6.9
CVE-2025-7705
Authentication bypass due to compatibility mode enabled by default
High
8.6
Affected Vendor
Affected Software
ABB Ability™ Symphony® Plus Operations, ABB Ability™ Symphony® Plus Historian
Vulnerable Versions:
unspecified
Timeline
Official Publish:
December 22nd, 2020
Last Modified:
September 16th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H