CVE-2020-24683
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network communication or endpoints for these applications are not protected, unauthorized actors can bypass authentication and make unauthorized connections to the server application.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.45%
- CWE
- CWE-602, CWE-305
- Published
- 2020-12-22
- Last modified
- 2026-03-14
Affected products
- ABB ABB Ability™ Symphony® Plus Operations
Weakness type
Related vulnerabilities
- CVE-2026-23478 — Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
- CVE-2025-33025 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2025-33024 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2025-32469 — A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio
- CVE-2023-0750 — Yellowbrik PEC-1864 authentication bypass
- CVE-2022-20658 — Cisco Unified Contact Center Management Portal and Unified Contact Center Domain Manager Privilege Escalation Vulnerability
- CVE-2022-1525 — Cognex 3D-A1000 Dimensioning System Client-Side Enforcement of Server-Side Security
- CVE-2026-25737 — Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)