SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-24679

An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.

CRITICAL 9.8EPSS 1.81%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.81% probability · 77th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
abb/symphony \+ historian · abb/symphony \+ operations
Source
cybersecurity@ch.abb.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.