Learn about CVE-2020-24680 affecting ABB's Symphony Plus Operations and Historian. Discover the impact, affected versions, and mitigation steps for this high-severity vulnerability.
In S+ Operations and S+ Historian, the passwords of internal users are encrypted but improperly stored in a database.
Understanding CVE-2020-24680
This CVE involves the improper storage of internal user passwords in ABB's Symphony Plus Operations and Historian.
What is CVE-2020-24680?
This vulnerability pertains to the encryption but improper storage of internal user passwords within the Symphony Plus Operations and Historian systems.
The Impact of CVE-2020-24680
Technical Details of CVE-2020-24680
This section provides detailed technical information about the vulnerability.
Vulnerability Description
The passwords of internal users in Symphony Plus Operations and Historian are encrypted but stored improperly in a database.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability requires local access to exploit, with low privileges needed to impact confidentiality, integrity, and availability.
Mitigation and Prevention
Protect your systems from CVE-2020-24680 with these mitigation strategies.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates