Weak Password Reset Rules Vulnerability Could Facilitate Unauthorized Access
CVE-2024-48845
9.8CRITICAL
What is CVE-2024-48845?
Weak password reset rules in ABB's ASPECT, NEXUS, and MATRIX Series products allow the storage of weak passwords. This vulnerability may lead to unauthorized administrative or application access, jeopardizing system security and data integrity. It highlights the importance of implementing robust password management practices to prevent exploitation and ensure the safety of sensitive information.
Affected Version(s)
ASPECT-Enterprise Linux 0 <= 3.07.02
MATRIX Series Linux 0 <= 3.07.02
NEXUS Series Linux 0 <= 3.07.02
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure