CVE-2020-24673: Abb Symphony + Historian
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system. This can lead to a loss of confidentiality and data integrity or even affect the product behavior and its availability.
Affected products
- Abb Symphony + Historian: version 3.0 only; version 3.1 only
- Abb Symphony + Operations: version 1.1 only; version 2.0 only; version 2.1 only; version 3.0 only; version 3.1 only; version 3.2 only; …
Published 2020-12-22. Last modified 2026-06-17.