|
209431
|
9.8 |
CRITICAL
Network
|
abb
|
symphony_\+_historian symphony_\+_operations
|
A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the serv…
|
CWE-20
Improper Input Validation
|
CVE-2020-24679
|
2024-11-21 14:15 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209432
|
8.8 |
HIGH
Network
|
abb
|
symphony_\+_historian symphony_\+_operations
|
An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the po…
|
NVD-CWE-noinfo
|
CVE-2020-24678
|
2024-11-21 14:15 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209433
|
8.8 |
HIGH
Network
|
abb
|
symphony_\+_historian symphony_\+_operations
|
Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-24677
|
2024-11-21 14:15 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209434
|
7.8 |
HIGH
Local
|
abb
|
symphony_\+_historian symphony_\+_operations
|
In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and res…
|
NVD-CWE-noinfo
|
CVE-2020-24676
|
2024-11-21 14:15 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209435
|
9.8 |
CRITICAL
Network
|
abb
|
symphony_\+_historian symphony_\+_operations
|
In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the …
|
CWE-287
Improper Authentication
|
CVE-2020-24675
|
2024-11-21 14:15 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209436
|
8.8 |
HIGH
Network
|
abb
|
symphony_\+_historian symphony_\+_operations
|
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, exe…
|
CWE-863
Incorrect Authorization
|
CVE-2020-24674
|
2024-11-21 14:15 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209437
|
9.8 |
CRITICAL
Network
|
abb
|
symphony_\+_historian symphony_\+_operations
|
In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the …
|
CWE-89
SQL Injection
|
CVE-2020-24673
|
2024-11-21 14:15 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209438
|
8.0 |
HIGH
Adjacent
|
dlink
|
dsl2888a_firmware
|
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. It contains an execute_cmd.cgi feature (that is not reachable via the web user interface) that lets an …
|
CWE-78
OS Command
|
CVE-2020-24581
|
2024-11-21 14:15 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209439
|
7.5 |
HIGH
Adjacent
|
dlink
|
dsl2888a_firmware
|
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. Lack of authentication functionality allows an attacker to assign a static IP address that was once use…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-24580
|
2024-11-21 14:15 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209440
|
8.8 |
HIGH
Adjacent
|
dlink
|
dsl2888a_firmware
|
An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. An unauthenticated attacker could bypass authentication to access authenticated pages and functionality.
|
CWE-287
Improper Authentication
|
CVE-2020-24579
|
2024-11-21 14:15 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|