Sensitive System Information at Risk Due to Local File Inclusion Vulnerabilities
CVE-2024-51541

7.5HIGH

Key Information:

Vendor

Abb

Vendor
CVE Published:
5 December 2024

What is CVE-2024-51541?

ABB products ASPECT, NEXUS, and MATRIX Series versions v3.08.02 are susceptible to Local File Inclusion vulnerabilities. These flaws may enable malicious actors to gain unauthorized access to sensitive system information. This poses significant risks, including potential data exfiltration and compromise of system integrity, prompting immediate attention from organizations utilizing these affected products. Timely patching and mitigation strategies are essential to safeguard critical infrastructure from these vulnerabilities.

Affected Version(s)

ASPECT-Enterprise Linux 0 <= 3.08.02

MATRIX Series Linux 0 <= 3.08.02

NEXUS Series Linux 0 <= 3.08.02

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABB likes to thank Gjoko Krstikj, Zero Science Lab, for reporting the vulnerabilities in responsible disclosure
.
CVE-2024-51541 : Sensitive System Information at Risk Due to Local File Inclusion Vulnerabilities