CVE-2020-24683: Abb Symphony + Historian
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network communication or endpoints for these applications are not protected, unauthorized actors can bypass authentication and make unauthorized connections to the server application.
Affected products
- Abb Symphony + Historian: version 3.0 only; version 3.1 only
- Abb Symphony + Operations: version 1.1 only; version 2.0 only; version 2.1 only; version 3.0 only; version 3.1 only; version 3.2 only; …
Published 2020-12-22. Last modified 2026-06-17.