CVE-2023-0228

Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ABBCNA
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
VendorProductVersion
abbsymphony_plus_s\+_operations
2.0 ≤
𝑥
< 2.1
abbsymphony_plus_s\+_operations
3.0 ≤
𝑥
< 3.3
abbsymphony_plus_s\+_operations
2.1
abbsymphony_plus_s\+_operations
2.1:sp2
abbsymphony_plus_s\+_operations
2.2
abbsymphony_plus_s\+_operations
3.3
abbsymphony_plus_s\+_operations
3.3:sp1
abbsymphony_plus_s\+_operations
3.3:sp2
𝑥
= Vulnerable software versions