Stored Cross Site Scripting Vulnerability in ABB ASPECT and Related Products
CVE-2024-13958
4.6MEDIUM
What is CVE-2024-13958?
A stored cross-site scripting vulnerability is present in ABB's ASPECT products when administrator credentials are compromised. This issue affects multiple product lines, including ASPECT-Enterprise, NEXUS Series, and MATRIX Series, all within versions up to 3.*. Exploitation of this vulnerability could allow attackers to inject malicious scripts, which might lead to unauthorized access and data breaches. It is critical for administrators to ensure strong credential management practices to mitigate the risks associated with this vulnerability.
Affected Version(s)
ASPECT-Enterprise Linux 0 <= 3.*
MATRIX Series Linux 0 <= 3.*
NEXUS Series Linux 0 <= 3.*
References
CVSS V4
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure