ABB Ability Symphony Plus
ABB Ability Symphony Plus (S+ Operations) contains an authentication bypass vulnerability that allows an unauthorized client to connect to the HMI network servers and act as a legitimate operator without providing credentials. Successful exploitation would allow an attacker to issue commands to control manufacturing processes. The vulnerability affects S+ Operations versions 2.1 SP2 and earlier, 2.2, 3.3 SP1, and 3.3 SP2. ABB has announced security updates are planned for Q3 2023 (for 3.3 SP2) and Q4 2023 (for other versions), with users of 2.1 SP2 and earlier advised to upgrade to version 3.3.
- Network access to the S+ Operations server on the HMI network
- No valid client credentials required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/8b5b4b58-7b27-4f61-b12f-99052aab803dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.