CVE-2023-0228

EUVD-2023-12313
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ABBCNA
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
Affected Products (NVD)
VendorProductVersion
abbsymphony_plus_s\+_operations
2.0 ≤
𝑥
< 2.1
abbsymphony_plus_s\+_operations
3.0 ≤
𝑥
< 3.3
abbsymphony_plus_s\+_operations
2.1
abbsymphony_plus_s\+_operations
2.1:sp2
abbsymphony_plus_s\+_operations
2.2
abbsymphony_plus_s\+_operations
3.3
abbsymphony_plus_s\+_operations
3.3:sp1
abbsymphony_plus_s\+_operations
3.3:sp2
𝑥
= Vulnerable software versions