CVE-2020-24675: Abb Symphony + Historian

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process.

Affected products

  • Abb Symphony + Historian: version 3.0 only; version 3.1 only
  • Abb Symphony + Operations: version 1.1 only; version 2.0 only; version 2.1 only; version 3.0 only; version 3.1 only; version 3.2 only; …

Published 2020-12-22. Last modified 2026-06-17.