Potential Cross Site Request Forgery Vulnerability Exposes Sensitive Information or Changes System Settings
CVE-2024-48846

7.3HIGH

Key Information:

Vendor

Abb

Vendor
CVE Published:
5 December 2024

What is CVE-2024-48846?

A cross site request forgery vulnerability has been identified in various ABB products, allowing potential attackers to exploit user sessions without proper authorization. This vulnerability can lead to unauthorized data exposure or changes in system settings, posing a significant risk to the security and integrity of the affected systems. Users of ABB ASPECT - Enterprise, NEXUS Series, and MATRIX Series v3.08.02 should implement appropriate security measures to safeguard their systems from potential exploitation.

Affected Version(s)

ASPECT-Enterprise Linux 0 <= 3.08.02

MATRIX Series Linux 0 <= 3.08.02

NEXUS Series Linux 0 <= 3.08.02

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure
.